Impact
The WP Directory Kit plugin for WordPress is vulnerable to a time‑based SQL injection that is triggered by the 'display_name' profile field. The attacker must first store a specially crafted value containing a single quote in their own profile; the plugin then later re‑reads that value and unsafely concatenates it into an SQL statement. The flaw permits appended queries, enabling an authenticated subscriber or higher to read or modify sensitive database information.
Affected Systems
WP Directory Kit plugin for WordPress, all versions up to and including 1.5.9.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. An attacker needs only subscriber‑level access to an instance of the plugin and can exploit the second‑order injection by first setting a malicious display_name and then triggering the update routine. The scope is limited to the affected WordPress site but may expose privileged database data to the authenticated user.
OpenCVE Enrichment