Input validation vulnerability in WP Directory Kit 1.1.9

The WP Directory Kit plugin for WordPress has a security vulnerability in versions up to 1.1.9. This weakness means that people who are not authenticated on the website can alter the plugin’s settings and add malicious JavaScript if they can get a site administrator to perform an action like clicking a link. This is because the ‘insert’ function of the plugin does not have proper security measures in place.

Detected in:

WP Directory Kit open vulnerable versions: >= * <= 1.1.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.