Impact
The WP Directory Kit WordPress plugin before version 1.5.6 fails to sanitize and escape user supplied input in the search_location and search_category parameters. This omission allows an unauthenticated attacker to inject arbitrary SQL statements through the search interface when a non‑default search field type is configured. If the injected query succeeds, the attacker could read, modify or delete database contents, thereby compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
All WordPress installations running WP Directory Kit plugin versions older than 1.5.6 are susceptible. The plugin provides directory functionality exposed via web forms, and any site that has not upgraded to the fixed release (1.5.6 or later) remains vulnerable.
Risk and Exploitability
Because the vulnerability is exploitable without any credentials, the attack surface is unrestricted. Exploitation would involve sending a crafted search request containing malicious SQL to the vulnerable endpoint, which would execute the query against the backend database. While no EPSS score is currently available, the absence of authentication requirements and the high potential impact render this a severe risk. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment