CyberRota Analysis
AI-GeneratedThe WP Directory Kit plugin for WordPress prior to version 1.5.5 lacks proper authorization and nonce checks on an authenticated AJAX action, enabling any authenticated user, including those with minimal permissions like Subscribers, to access sensitive information such as the site's user list and unpublished listings of other users. This vulnerability poses a significant risk to user privacy and data integrity. WordPress site administrators and security teams should prioritize updating to the latest version of the plugin to mitigate potential data exposure.
Original NVD Description
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users.