Unauthenticated SQL Injection in Directory Pro Plugin by WordPress
CVE-2026-66649
9.3CRITICAL
What is CVE-2026-66649?
An unauthenticated SQL Injection vulnerability exists in the Directory Pro plugin, affecting versions up to 2.5.8. This flaw allows attackers to execute arbitrary SQL queries, potentially compromising the integrity and confidentiality of the database. Without proper authentication, unauthorized users can exploit this weakness, making it crucial for site administrators to apply necessary updates and ensure their systems are secure.
Affected Version(s)
Directory Pro <= 2.5.8