Description
The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.
Published: 2026-09-15
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection via unsanitized widget settings
Action: Patch Now
AI Analysis

Impact

The WP Directory Kit plugin, up to version 1.5.7, fails to escape certain Elementor Category and Location widget configuration values before embedding them in a SQL statement. This flaw, identified as CWE‑89, allows authenticated users who have Editor or higher access to the page builder to inject arbitrary SQL code that is executed when the affected page is rendered. The injection could let the attacker read, modify, or delete database contents, potentially undermining data confidentiality, integrity, and availability.

Affected Systems

WordPress sites running WP Directory Kit version 1.5.7 or older are affected. Any user that holds Editor or higher permissions within the page builder interface can trigger the injection. The vulnerability is confined to the plugin; no other WordPress components are directly impacted.

Risk and Exploitability

The CVSS score of 6.8 indicates a high severity for authenticated attackers. The EPSS score of less than 1% suggests that, while the flaw is rare, judged through current exploit data, active exploitation is uncommon. Because the attack requires legitimate Editor+ access, the vector is limited to authenticated users. The vulnerability is not listed in the CISA KEV catalog, meaning there is no current record of widespread exploitation. However, any compromised or compromised accounts could leverage the flaw to compromise the site's database.

Generated by OpenCVE AI on September 20, 2026 at 17:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Directory Kit to the latest version (≥1.5.8) which properly sanitizes widget settings before SQL usage.
  • If an upgrade is not possible, remove or disable the Elementor Category and Location widgets so that the vulnerable code paths are no longer exercised.
  • Restrict Editor or higher roles to trusted administrators and consider removing or disabling page‑builder access for users who do not require it.

Generated by OpenCVE AI on September 20, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.
Title WP Directory Kit <= 1.5.7 - Editor+ SQL Injection via Elementor Category and Location Widget Settings
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-15T14:26:11.676Z

Reserved: 2026-07-22T13:47:39.215Z

Link: CVE-2026-16593

cve-icon Vulnrichment

Updated: 2026-09-15T14:26:08.333Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T06:16:57.370

Modified: 2026-09-16T20:25:29.240

Link: CVE-2026-16593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:00:14Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')