Unauthenticated SQL Injection in WP Directory Kit by WordPress
CVE-2026-27538

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-27538?

An unauthenticated SQL injection vulnerability exists in the WP Directory Kit plugin for WordPress, affecting versions up to 1.5.4. This flaw allows attackers to manipulate database queries without authentication, potentially exposing sensitive data or compromising the integrity of the application. It is crucial for users of affected versions to implement security updates and maintain best practices to mitigate potential risks.

Affected Version(s)

WP Directory Kit <= 1.5.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Taylsec | Patchstack Bug Bounty Program
.