Impact
The WP Directory Kit plugin for WordPress versions up to and including 1.5.4 contains an unauthenticated SQL Injection flaw. The vulnerability allows an attacker to manipulate the SQL queries executed by the plugin, potentially reading, modifying, or deleting data stored in the WordPress database. If the application's database user credentials have high privileges, the attacker could also achieve remote code execution or full system compromise. The weakness is a classic input validation failure identified as CWE-89.
Affected Systems
The affected product is the WP Directory Kit plugin for WordPress, versions 1.5.4 and earlier. All installations of the plugin that have not been upgraded to the latest release are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, placing it in the High severity range. No EPSS score is currently available, indicating limited publicly documented exploitation or lack of data. The vulnerability is not listed in CISA's KEV catalog, but its high severity and unauthenticated nature make it a top priority for remediation. An attacker could exploit this flaw by sending specially crafted HTTP requests to the plugin’s endpoints without needing credentials, which then leads to arbitrary SQL commands being executed against the database.
OpenCVE Enrichment