CVE-2026-18473: WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter
Published Aug 9, 2026
·Updated
The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.
Affected Software
1 affected component
WordPress plugin: WP Directory Kit<1.5.5
Event History
Aug 9, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness