Impact
The WP Directory Kit WordPress plugin version prior to 1.5.6 does not sanitize or escape a section parameter used in an authenticated AJAX action that lacks an authorization check. This flaw permits any authenticated user, including those with the Subscriber role, to inject arbitrary SQL statements. An attacker could read, modify, or delete data within the WordPress database, potentially compromising site integrity and confidentiality.
Affected Systems
The vulnerability affects the WP Directory Kit plugin for WordPress, specifically all releases before 1.5.6. The plugin is associated with an undefined vendor but is listed under the WordPress plugin directory. No specific PHP version or CMS version constraints are noted.
Risk and Exploitability
The flaw is a high‑severity SQL injection, but no CVSS score is publicly available for this entry. Because the attack vector requires authentication and the vulnerable endpoint lacks an access control check, the risk is limited to users who can log into the site, such as Subscribers. The EPSS score is not available, but the absence of a key indicates that exploitation probability is not quantified. This vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment