CyberRota Analysis
AI-GeneratedThe WP Directory Kit plugin for WordPress, up to version 1.5.7, is vulnerable due to inadequate authorization checks in its shortcode functionality, allowing users with Contributor roles to access and disclose non-public listing content, including sensitive information from other users. This vulnerability poses a significant risk to user privacy and data security. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure.
Original NVD Description
The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-protected and hidden fields, belonging to other users.