WP Directory Kit Plugin Vulnerability

CRITICAL (10.0)

Threat Intelligence

⚠️ CRITICAL GAP - Exploits exist but no detection available
EPSS Score: 0.30% chance of exploitation (percentile: 53%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: GitHub PoC

How we test →

What is it?

The WP Directory Kit plugin is a WordPress extension used to manage directories and listings on websites. This vulnerability allows attackers to bypass authentication and gain full administrative access to the website, potentially leading to unauthorized data access, modification, or deletion.

Am I affected?

You're affected if you use WP Directory Kit. Specific version info not stated in the advisory.

How to fix

Upgrade to WP Directory Kit version 2.0.5 or later from the official WordPress repository.
- Immediate mitigations:
- Restrict network access to your WordPress installation (firewall it from the public internet)
- Audit plugin and theme activity for suspicious access patterns
- Monitor for unauthorized login attempts