CVE-2024-37253 LOW

CVE-2024-37253: WordPress WPDirectoryKit plugin <= 1.3.6 - HTML Injection vulnerability

Vendor Wpdirectorykit
Product WP Directory Kit
Weakness CWE-74
Published July 9, 2024
Last update April 28, 2026

CVSS base score

2.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDirectoryKit WP Directory Kit allows Code Injection.This issue affects WP Directory Kit: from n/a through 1.3.6.

Explanation of Vulnerability in Simple Terms

02Summary

WP Directory Kit versions up to 1.3.6 contain an input validation flaw that allows high-privilege users to modify data they should not be able to change. The vulnerability requires administrator-level access and does not affect confidentiality or availability. A patch version has not been publicly identified.

What an attacker can do

03Attacker Capabilities

Modify data within the plugin if they have administrator access.

Potential impact on your site

04Site Impact

Administrators with malicious intent or compromised admin accounts could alter plugin data; non-admin users are unaffected.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level privileges on the WordPress site.

Key dates

06Disclosure timeline

July 9, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE