Pricing
Case studies
Login
Start trial
WP Directory Kit
wpdirectorykit
Developer
1.4.8
Latest version
3,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
17 fixed
12 Mitigation rules
Unauthenticated SQL Injection vulnerability
<= 1.4.7
1 day ago
Authentication Bypass to Privilege Escalation via Account Takeover vulnerability
1.4.0-1.4.4
Dec 3, 2025
Authenticated (Admin+) SQL Injection vulnerability
<= 1.4.6
Dec 1, 2025
Reflected Cross-Site Scripting via 'order_by' Parameter vulnerability
<= 1.4.5
Nov 27, 2025
Unauthenticated SQL Injection via select_2_ajax() Function vulnerability
<= 1.4.3
Nov 21, 2025
Broken Access Control vulnerability
<= 1.4.0
Sep 26, 2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.3.5
Jul 4, 2024
HTML Injection vulnerability
<= 1.3.6
Jun 26, 2024
Authenticated (Subscriber+) SQL Injection vulnerability
<= 1.3.0
Apr 5, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.2.9
Mar 25, 2024
Broken Access Control vulnerability
<= 1.2.6
Sep 5, 2023
Unauthenticated Local File Inclusion vulnerability
< 1.2.0
Jun 22, 2023
Missing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action vulnerability
<= 1.2.3
Jun 13, 2023
Reflected Cross-Site Scripting via 'search' vulnerability
<= 1.2.3
Jun 2, 2023
Multiple Cross-Site Request Forgery vulnerability
<= 1.2.1
May 4, 2023
Multiple Missing Authorization vulnerability
<= 1.2.2
May 4, 2023
Open Redirection vulnerability
<= 1.1.9
Apr 27, 2023