CVE-2026-16596: WP Directory Kit <= 1.5.4 - Authenticated (Custom+) SQL Injection via 'data_fields_list' Parameter
The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'datafieldslist' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to WordPress with custom-level access or higher. Unauthenticated visitors are not described as able to exploit it.
What could an attacker obtain through exploitation?
The injection can allow an attacker to append SQL to existing queries and extract sensitive information from the WordPress database. The provided information does not indicate database modification or service disruption.
Which installations are affected?
WP Directory Kit versions through 1.5.4, including 1.5.4, are affected. The issue is associated with the data_fields_list parameter.