Pricing
Case studies
Login
Start trial
WP Directory Kit
WPDirectoryKit
Developer
1.5.1
Latest version
3,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
18 patched
12 Mitigation rules
Unauthenticated Email Exposure via wdk_public_action vulnerability
<= 1.4.9
27/01/2026
Unauthenticated SQL Injection vulnerability
<= 1.4.7
16/12/2025
Authentication Bypass to Privilege Escalation via Account Takeover vulnerability
1.4.0-1.4.4
03/12/2025
Authenticated (Admin+) SQL Injection vulnerability
<= 1.4.6
01/12/2025
Reflected Cross-Site Scripting via 'order_by' Parameter vulnerability
<= 1.4.5
27/11/2025
Unauthenticated SQL Injection via select_2_ajax() Function vulnerability
<= 1.4.3
21/11/2025
Broken Access Control vulnerability
<= 1.4.0
26/09/2025
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.3.5
04/07/2024
HTML Injection vulnerability
<= 1.3.6
26/06/2024
Authenticated (Subscriber+) SQL Injection vulnerability
<= 1.3.0
05/04/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.2.9
25/03/2024
Broken Access Control vulnerability
<= 1.2.6
05/09/2023
Unauthenticated Local File Inclusion vulnerability
< 1.2.0
22/06/2023
Missing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action vulnerability
<= 1.2.3
13/06/2023
Reflected Cross-Site Scripting via 'search' vulnerability
<= 1.2.3
02/06/2023
Multiple Cross-Site Request Forgery vulnerability
<= 1.2.1
04/05/2023
Multiple Missing Authorization vulnerability
<= 1.2.2
04/05/2023
Open Redirection vulnerability
<= 1.1.9
27/04/2023