Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
WP Directory Kit
wpdirectorykit
Developer
1.4.4
Latest version
3,000
Installations
2 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
12 fixed
8 Mitigation rules
Broken Access Control vulnerability
<= 1.4.0
Sep 26, 2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.3.5
Jul 4, 2024
HTML Injection vulnerability
<= 1.3.6
Jun 26, 2024
Authenticated (Subscriber+) SQL Injection vulnerability
<= 1.3.0
Apr 5, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.2.9
Mar 25, 2024
Broken Access Control vulnerability
<= 1.2.6
Sep 5, 2023
Unauthenticated Local File Inclusion vulnerability
< 1.2.0
Jun 22, 2023
Missing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action vulnerability
<= 1.2.3
Jun 13, 2023
Reflected Cross-Site Scripting via 'search' vulnerability
<= 1.2.3
Jun 2, 2023
Multiple Cross-Site Request Forgery vulnerability
<= 1.2.1
May 4, 2023
Multiple Missing Authorization vulnerability
<= 1.2.2
May 4, 2023
Open Redirection vulnerability
<= 1.1.9
Apr 27, 2023