WPDirectoryKit is a WordPress directory plugin that occupies a notable position in the web-application vulnerability landscape despite its narrow product scope, owing to its use as a content-management and directory component across many sites. Vulnerabilities affecting the plugin skew toward serious outcomes and tend toward public exploit availability, concentrating in application-layer weakness classes including cross-site scripting, missing authorization, CSRF, path traversal, and injection flaws that are characteristic of WordPress plugins handling user input and privileged operations. Defenders should treat updates to this plugin as a priority for any WordPress deployment that uses it, and monitor for exploitation patterns in their access logs; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpdirectorykit over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13390CRITICAL The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication a | Dec 3, 2025 | 9.8 | 51 | NO | YES |
CVE-2025-13138HIGH The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1. | Nov 21, 2025 | 7.5 | 41 | NO | YES |
CVE-2026-42672CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.
This issue affe | Jun 1, 2026 | 9.3 | 37 | NO | NO |
CVE-2026-39531CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.
This issue affe | May 21, 2026 | 9.3 | 37 | NO | NO |
CVE-2025-13920MEDIUM The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This m | Jan 24, 2026 | 5.3 | 33 | NO | YES |
CVE-2023-41875CRITICAL Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory K | Dec 13, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-2278CRITICAL The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenti | Jun 13, 2023 | 9.8 | 28 | NO | NO |
CVE-2026-39534HIGH Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions. | Jun 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-13089HIGH The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to, and including, 1.4.7 due to in | Dec 13, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-3217HIGH The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to | Apr 5, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdirectorykit.
Media articles that mention a CVE ID that affects a product developed by Wpdirectorykit — matched by CVE ID, not by vendor name.