Impact
Unauthenticated SQL injection exists in WordPress WP Directory Kit plugin versions 1.5.4 and older, exposing a classic CWE‑89 flaw. An attacker can inject arbitrary SQL through unsanitised input fields in the plugin, potentially reading, altering, or deleting data stored in the WordPress database. The vulnerability is not limited to a single user; anyone who can reach the affected URLs can trigger it, giving the intruder a broad attack surface and the ability to compromise site integrity.
Affected Systems
The issue affects the WP Directory Kit plugin distributed by WPDirectoryKit for WordPress. All installations using version 1.5.4 or earlier are vulnerable. No other WordPress components are affected unless the plugin is misconfigured to expose additional endpoints.
Risk and Exploitability
The CVSS score for this vulnerability is 7.5, indicating moderate severity. The EPSS score is not available but the advisory notes that the flaw is unauthenticated, meaning an attacker does not need to bypass authentication. Because any visitor might exploit the exposed input, the likelihood of exploitation is relatively high, especially on publicly accessible sites. The vulnerability is not listed in the CISA KEV catalog, but the potential impact on data confidentiality and integrity warrants urgent remediation.
OpenCVE Enrichment