Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-18473: WP Directory Kit Plugin SQL Injection Risk
CVE-2026-18473 · published 26 days ago
Summary
The WP Directory Kit plugin for WordPress is vulnerable to SQL injection attacks if an attacker knows the right input. This could allow them to access or modify sensitive data. Update the plugin to version 1.5.5 or later to fix this issue.
What to do
- Update unknown wp directory kit to version 1.5.5 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | wp directory kit | < 1.5.5 |
Original advisory text
WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter
The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
References
- https://wpscan.com/vulnerability/a5596bc1-5ae9-4141-b027-85a0b91ecdab/ exploit vdb-entry technical-description
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
Timeline
Published9 Aug 2026
Updated29 Aug 2026
First seen9 Aug 2026
Monitor software like this
Free during beta