Junglewise Threat Intelligence

CVE-2026-66649: Directory Pro SQL injection [unauthenticated]

CVE-2026-66649 · Severity: critical · CVSS 9.3 · Published 2026-08-20

Executive brief

Directory Pro is a popular WordPress plugin for creating business directory listings. This vulnerability allows attackers without authentication to inject malicious SQL commands, potentially exposing, modifying, or deleting the entire database including user accounts and sensitive customer data.

Technical details

The vulnerability is an unauthenticated SQL injection flaw in Directory Pro plugin versions 2.5.8 and earlier. The attack vector is network-based and requires no authentication or user interaction—an attacker can directly craft malicious SQL queries through a vulnerable input vector. Successful exploitation allows attackers to read, modify, or delete arbitrary data in the database. At publication, no official patch was available, though Patchstack has issued a mitigation rule to block exploit attempts.

Affected products

  • Patchstack Directory Pro <= 2.5.8

Timeline

  • 2026-08-20: disclosed: Published on NVD and Patchstack
  • 2026-01-26: other: Initially reported to Patchstack

References