WordPress Plugin Vulnerabilities

WP Directory Kit <= 1.5.9 - Unauthenticated Unpublished Listing Disclosure via search_suggestion

Description

The plugin does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved listings belonging to other users.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Erwan LR (WPScan)
Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-09-12 (about 23 days ago)
Added
2026-09-05 (about 1 month ago)
Last Updated
2026-09-23 (about 11 days ago)

Other