CVE-2026-16589: WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter
Published Aug 8, 2026
·Updated
The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.
Affected Software
1 affected component
WordPress plugin "WP Directory Kit"<1.5.5
Event History
Aug 8, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16589?
CVE-2026-16589 has a risk severity score of 75.
2
How do I fix CVE-2026-16589?
To fix CVE-2026-16589, update the WP Directory Kit plugin to version 1.5.5 or later.
3
Who is affected by CVE-2026-16589?
CVE-2026-16589 affects all users of the WP Directory Kit plugin prior to version 1.5.5.
4
What type of vulnerability is CVE-2026-16589?
CVE-2026-16589 is classified as an SQL Injection vulnerability.
5
Can unauthorized users exploit CVE-2026-16589?
No, only authenticated users, such as Subscribers, can exploit CVE-2026-16589 due to insufficient authorization checks.