Access violation vulnerability in WP Directory Kit 1.1.9

The WP Directory Kit plugin for WordPress is a vulnerable program that could be exploited by attackers. In versions up to and including 1.1.9, attackers can use a function called ‘wdk_public_action’ to include and execute arbitrary files on the server. This means that attackers can bypass access controls, obtain confidential data, and even execute code if they can upload images or other files that are thought to be safe.

Detected in:

WP Directory Kit open vulnerable versions: >= * <= 1.1.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.