Impact
The WP Directory Kit plugin permits authenticated attackers who possess custom‑level access or higher to exploit a blind SQL Injection through the 'order_by' parameter. The plugin’s lack of proper input escaping and the absence of prepared statements allow an attacker to append arbitrary SQL queries, enabling extraction of sensitive information from the database.
Affected Systems
The flaw appears in all releases of the WP Directory Kit WordPress plugin up to and including version 1.5.4. Any WordPress site using the plugin within this version range is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 categorizes the vulnerability as moderate severity, while the EPSS of less than 1% indicates a low likelihood of active exploitation. It is not listed in the CISA KEV catalog. Attackers need a valid WordPress account with custom‑level privileges or higher, meaning that the risk is confined to sites where such users exist. Although the probability of exploitation is low, the potential impact of data exposure warrants timely mitigation.
OpenCVE Enrichment