Blind SQL Injection Vulnerability in WP Directory Kit Plugin for WordPress
CVE-2026-16588
6.5MEDIUM
What is CVE-2026-16588?
The WP Directory Kit plugin for WordPress is susceptible to a blind SQL injection vulnerability through the 'order_by' parameter, affecting all versions up to and including 1.5.4. This weakness arises from inadequate escaping of user-supplied parameters and insufficient preparation of SQL queries. Authenticated attackers with custom-level access can exploit this flaw to inject additional SQL queries, potentially allowing them to retrieve sensitive information stored in the database.
Affected Version(s)
WP Directory Kit 0 <= 1.5.4