Wp Directory Kit
Vendor:
First CVE: Jun 2, 2023 · Active for 3 years
22
Total CVEs
More Total CVEs than 94% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wp Directory Kit over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2023
3 years ago
Most Recent CVE
Jun 15, 2026
39 days ago
CVE Severity & Scoring
Wp Directory Kit22 CVEs
55%
18%
23%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (68.2%)
Unknown0 (0.0%)
Required7 (31.8%)
Privileges Required
Low2 (9.1%)
High2 (9.1%)
None18 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13390CRITICAL The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication a | Dec 3, 2025 | 9.8 | 51 | NO | YES |
CVE-2025-13138HIGH The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1. | Nov 21, 2025 | 7.5 | 41 | NO | YES |
CVE-2026-42672CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.
This issue affe | Jun 1, 2026 | 9.3 | 37 | NO | NO |
CVE-2026-39531CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.
This issue affe | May 21, 2026 | 9.3 | 37 | NO | NO |
CVE-2025-13920MEDIUM The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This m | Jan 24, 2026 | 5.3 | 33 | NO | YES |
CVE-2023-41875CRITICAL Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory K | Dec 13, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-2278CRITICAL The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenti | Jun 13, 2023 | 9.8 | 28 | NO | NO |
CVE-2026-39534HIGH Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions. | Jun 15, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-13089HIGH The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to, and including, 1.4.7 due to in | Dec 13, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-3217HIGH The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, 1.3.0 due to | Apr 5, 2024 | 8.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
13.6% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Wp Directory Kit
Top CWEs
Versions
No cataloged versions.