References https://wpscan.com/plugin/wpdirectorykit/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit/wp-directory-kit-119-unauthenticated-local-file-inclusion-via-wdk-public-action https://github.com/advisories/GHSA-476f-cw6x-q8j7 https://pentest-tools.com/vulnerabilities-exploits/wp-directory-kit-143-unauthenticated-sql-injection_28772 https://patchstack.com/database/wordpress/plugin/wpdirectorykit/vulnerability/wordpress-wp-directory-kit-plugin-1-4-6-authenticated-admin-sql-injection-vulnerability https://ryankozak.com/posts/cve-2025-13390/ https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wpdirectorykit/wp-directory-kit-123-reflected-cross-site-scripting-via-search https://github.com/advisories/GHSA-cmp6-j4f4-vm9f https://github.com/advisories/GHSA-39hf-cw8g-g4qj https://avd.aliyun.com/detail?id=AVD-2024-3217 https://cve.imfht.com/detail/CVE-2024-3217 https://www.dptech.com/index.php?m=content&c=index&a=show&catid=75&id=5715 https://avd.aliyun.com/detail?id=AVD-2023-2278
Related VulnerabilitiesPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL FetchPoCCVE-2026-87902: WordPress Core - PHP Template Path TraversalPoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCCVE-2026-84434: WordPress Gravity Forms Plugin <=3.1.0.4 - Unauthenticated Arbitrary File UploadPoCwordpress-click2shell: WordPress Click2Shell Theme Preview Selector InjectionPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDORPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞Wordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2022-1281: Photo Gallery WordPress v1.6.3 - SQL InjectionPoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation