CVE-2026-18653

CVE-2026-18653CVE-2026-18653

Description

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach.

Scoring

Last modified2026-08-16
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.