cleantalk
Vulnerabilities and Security Researches

WP Directory Kit, CVE-2023-2351

CVE, Research URL

CVE-2023-2351

Application

WP Directory Kit

Published on
Jun 13, 2023
Research Description
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajax_admin' function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to delete or change plugin settings, import demo data, delete Directory Kit related posts and terms, and install arbitrary plugins. A partial patch was introduced in version 1.2.0.
Affected versions
max 1.2.4.
Status
vulnerable