The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.
CVE-2026-16593
NONE
Обновлено 15 сентября 2026
WordPress
Сводка
CVE ID
CVE-2026-16593
Опубликовано
15 сентября, 2026
Поставщик
WordPress
Уровень угрозы
NONE
Ущерб
Минимальное воздействие
Ссылка
Перейти к источнику