Impact
The WP Directory Kit WordPress plugin version prior to 1.5.6 does not sanitize or escape a section parameter used in an authenticated AJAX action that lacks an authorization check, resulting in a CWE-89 SQL injection vulnerability. This flaw permits any authenticated user, including those with the Subscriber role, to inject arbitrary SQL statements. An attacker could read, modify, or delete data within the WordPress database, potentially compromising site integrity and confidentiality.
Affected Systems
The vulnerability affects the WP Directory Kit plugin for WordPress, specifically all releases before 1.5.6. The plugin is associated with an undefined vendor but is listed under the WordPress plugin directory. No specific PHP version or CMS version constraints are noted.
Risk and Exploitability
The flaw is a high‑severity SQL injection with a publicly available CVSS score of 8.1, indicating significant impact. Because the attack vector requires authentication and the vulnerable endpoint lacks an authorization check, the risk is limited to users who can log into the site, such as Subscribers. The EPSS score is < 1%, indicating a low probability of exploitation, and this vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment