CVE-2023-2351: WP Directory Kit <= 1.2.3 - Missing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action
The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'ajaxadmin' function in versions up to, and including, 1.2.3. This makes it possible for authenticated attackers with subscriber-level permissions or above to delete or change plugin settings, import demo data, delete Directory Kit related posts and terms, and install arbitrary plugins. A partial patch was introduced in version 1.2.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2351?
CVE-2023-2351 has a high severity rating due to its potential for unauthorized data modification and loss.
How do I fix CVE-2023-2351?
To fix CVE-2023-2351, update the WP Directory Kit plugin to version 1.2.4 or later.
Who is affected by CVE-2023-2351?
Authenticated users with subscriber-level permissions on WordPress sites using affected versions of the WP Directory Kit plugin are at risk.
What functionality is compromised in CVE-2023-2351?
CVE-2023-2351 compromises the security of the 'ajax_admin' function due to a missing capability check.
What versions of the WP Directory Kit are impacted by CVE-2023-2351?
Versions of the WP Directory Kit plugin up to and including 1.2.3 are impacted by CVE-2023-2351.