WordPress Plugin Vulnerabilities

WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowindow

Description

The plugin does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-09-12 (about 2 days ago)
Added
2026-09-05 (about 9 days ago)
Last Updated
2026-09-05 (about 9 days ago)

Other