Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpdirectorykit

First CVE: Jun 2, 2023Active for: 3 yearsTotal CVEs: 22
48.5
VTI Score
High

WPDirectoryKit is a WordPress directory plugin that occupies a notable position in the web-application vulnerability landscape despite its narrow product scope, owing to its use as a content-management and directory component across many sites. Vulnerabilities affecting the plugin skew toward serious outcomes and tend toward public exploit availability, concentrating in application-layer weakness classes including cross-site scripting, missing authorization, CSRF, path traversal, and injection flaws that are characteristic of WordPress plugins handling user input and privileged operations. Defenders should treat updates to this plugin as a priority for any WordPress deployment that uses it, and monitor for exploitation patterns in their access logs; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpdirectorykit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2023
3 years ago
Most Recent CVE
Jun 15, 2026
39 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-13390CRITICAL
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication a
Dec 3, 20259.851NOYES
CVE-2025-13138HIGH
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1.
Nov 21, 20257.541NOYES
CVE-2026-42672CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affe
Jun 1, 20269.337NONO
CVE-2026-39531CRITICAL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affe
May 21, 20269.337NONO
CVE-2025-13920MEDIUM
The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This m
Jan 24, 20265.333NOYES
CVE-2023-41875CRITICAL
Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory K
Dec 13, 20249.829NONO
CVE-2023-2278CRITICAL
The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenti
Jun 13, 20239.828NONO
CVE-2026-39534HIGH
Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
Jun 15, 20267.526NONO
CVE-2025-13089HIGH
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to, and including, 1.4.7 due to in
Dec 13, 20257.526NONO
CVE-2024-3217HIGH
The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to
Apr 5, 20248.825NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
55%
18%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (68.2%)
Unknown0 (0.0%)
Required7 (31.8%)
Privileges Required
Low2 (9.1%)
High2 (9.1%)
None18 (81.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
13.6% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpdirectorykit.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpdirectorykit — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpdirectorykit's Products

View all 2 CNAs →

Top CWEs