Executive brief
WP Directory Kit, a WordPress plugin used to create and manage business directories, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to interact directly with the website's database. Successful exploitation could lead to the theft of sensitive customer data, unauthorized access to administrative information, or disruption of the website's operations.
Technical details
The WP Directory Kit plugin for WordPress is vulnerable to Blind SQL Injection due to improper neutralization of special elements in SQL commands. The flaw exists in versions up to and including 1.5.0. An unauthenticated remote attacker can exploit this vulnerability by sending specially crafted web requests to the server, allowing them to extract sensitive information from the database through inference (blind injection). The vulnerability has been assigned a CVSS score of 9.3, reflecting its high impact on confidentiality and potential for mass exploitation. Users are advised to update to version 1.5.1 or later to remediate the issue.
Affected products
- Wp Directory Kit WP Directory Kit <= 1.5.0
Timeline
- 2026-02-17: other: Reported by researcher Martín Martín
- 2026-04-13: advisory: Initial advisory published by Patchstack
- 2026-05-21: disclosed: CVE published to NVD dataset