CyberRota Analysis
AI-GeneratedThe WP Directory Kit plugin for WordPress, prior to version 1.5.5, lacks proper authorization and nonce checks on certain authenticated AJAX actions, enabling any authenticated user, including those with low-level permissions like Subscribers, to access and retrieve stored contact messages and sensitive user data from other accounts. This vulnerability poses a significant risk to user privacy and data integrity. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.