Impact
The WP Directory Kit plugin, up to version 1.5.7, fails to escape certain Elementor Category and Location widget configuration values before embedding them in a SQL statement. This flaw, identified as CWE‑89, allows authenticated users who have Editor or higher access to the page builder to inject arbitrary SQL code that is executed when the affected page is rendered. The injection could let the attacker read, modify, or delete database contents, potentially undermining data confidentiality, integrity, and availability.
Affected Systems
WordPress sites running WP Directory Kit version 1.5.7 or older are affected. Any user that holds Editor or higher permissions within the page builder interface can trigger the injection. The vulnerability is confined to the plugin; no other WordPress components are directly impacted.
Risk and Exploitability
The CVSS score of 6.8 indicates a high severity for authenticated attackers. The EPSS score of less than 1% suggests that, while the flaw is rare, judged through current exploit data, active exploitation is uncommon. Because the attack requires legitimate Editor+ access, the vector is limited to authenticated users. The vulnerability is not listed in the CISA KEV catalog, meaning there is no current record of widespread exploitation. However, any compromised or compromised accounts could leverage the flaw to compromise the site's database.
OpenCVE Enrichment