Executive brief
Directory Pro is a popular WordPress plugin for creating business directory listings. This vulnerability allows attackers without authentication to inject malicious SQL commands, potentially exposing, modifying, or deleting the entire database including user accounts and sensitive customer data.
Technical details
The vulnerability is an unauthenticated SQL injection flaw in Directory Pro plugin versions 2.5.8 and earlier. The attack vector is network-based and requires no authentication or user interaction—an attacker can directly craft malicious SQL queries through a vulnerable input vector. Successful exploitation allows attackers to read, modify, or delete arbitrary data in the database. At publication, no official patch was available, though Patchstack has issued a mitigation rule to block exploit attempts.
Affected products
- Patchstack Directory Pro <= 2.5.8
Timeline
- 2026-08-20: disclosed: Published on NVD and Patchstack
- 2026-01-26: other: Initially reported to Patchstack