← WordPress Vulnerabilities
WordPress security by component

WP Directory Kit

WP Directory Kit is a WordPress component with 16 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: wpdirectorykit

CVE-2026-39534: WP Directory Kit: A security weakness

WP Directory Kit is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.5.0.

PublishedJun 15, 2026
Known safe version1.5.1
Safe version
Jun 15, 2026 CVE-2026-39534
WP Directory Kit: A security weakness
WP Directory Kit is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.5.0.
1.5.1
CVE7.5
NVDPending
Jun 01, 2026 CVE-2026-42672
WP Directory Kit: SQL injection
WP Directory Kit is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.5.1.
1.5.2
CVE9.3
NVDPending
May 21, 2026 CVE-2026-39531
WP Directory Kit: SQL injection
WP Directory Kit is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.5.0.
1.5.1
CVE9.3
NVDPending
Nov 27, 2025 CVE-2025-13525
WP Directory Kit: Cross-site scripting
WP Directory Kit is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Nov 21, 2025 CVE-2025-13138
WP Directory Kit: SQL injection
WP Directory Kit is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Sep 26, 2025 CVE-2025-60120
WP Directory Kit: A security weakness
WP Directory Kit is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jul 21, 2024 CVE-2024-37487
WP Directory Kit: Cross-site scripting
WP Directory Kit is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Jul 09, 2024 CVE-2024-37253
WP Directory Kit: Code execution
WP Directory Kit is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE2.7
NVD2.7
Apr 05, 2024 CVE-2024-3217
WP Directory Kit: SQL injection
WP Directory Kit is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Mar 27, 2024 CVE-2024-29774
WP Directory Kit: Cross-site scripting
WP Directory Kit is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Dec 29, 2023 CVE-2023-31229
WP Directory Kit: An open redirect
WP Directory Kit is affected by an open redirect. Exposure depends on how the affected operation is made reachable by the site. A crafted link can redirect visitors from the trusted site to an attacker-controlled destination.
See mitigation notes
CVE4.7
NVD6.1
Aug 31, 2023 CVE-2023-2279
WP Directory Kit: Cross-site request forgery
WP Directory Kit is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Jun 13, 2023 CVE-2023-2351
WP Directory Kit: A security weakness
WP Directory Kit is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD4.3
Jun 13, 2023 CVE-2023-2278
WP Directory Kit: Filesystem traversal
WP Directory Kit is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.8
NVD9.8
Jun 13, 2023 CVE-2023-2277
WP Directory Kit: Cross-site request forgery
WP Directory Kit is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE6.1
NVD4.7
Jun 09, 2023 CVE-2023-2280
WP Directory Kit: A security weakness
WP Directory Kit is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD5.3