CVE-2026-18473

NONE
Updated Aug 09, 2026
WordPress
Parameter Value
Affected Versions before 1.5.5
Type CWE-89 SQL Injection
Vendor WordPress
Public PoC No

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

Weakness Type (CWE)

Vulnerable Products

unknown:wp directory kit