Impact
The WP Directory Kit plugin for WordPress is vulnerable to a generic SQL injection through the 'data_fields_list' parameter. Because the plugin does not properly escape user input or prepare the existing SQL query, an attacker who is authenticated with at least custom-level permissions can append and execute arbitrary SQL statements. This can enable the extraction of sensitive data from the database, compromising confidentiality.
Affected Systems
All WordPress installations running WP Directory Kit versions 1.5.4 or earlier are affected. The vulnerability exists in the plugin code that processes the 'data_fields_list' parameter and is present in every release up to 1.5.4, regardless of site size or configuration.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation in the wild cannot be determined, yet the vulnerability is not listed in the CISA KEV catalog. The exploit requires an authenticated user with custom or higher capabilities, meaning that the risk level depends on the permission set exposed on the affected WordPress site. If the platform allows non‑admin users to have custom permissions, the attack vector becomes realistic and the potential impact is data theft from the database.
OpenCVE Enrichment