CVE-2026-18653: WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter
The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP Directory Kit WordPress pluginto a version that resolves this vulnerability.Fixed in 1.5.7 - Compensating control
On multisite installations, limit administrative access so that an admin of a single site cannot perform actions that would allow reading data from the entire network.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18653?
CVE-2026-18653 has a risk score of 47, indicating a high severity vulnerability.
How do I fix CVE-2026-18653?
To fix CVE-2026-18653, update the WP Directory Kit plugin to version 1.5.7 or later.
What type of vulnerability is CVE-2026-18653?
CVE-2026-18653 is classified as an SQL injection vulnerability.
Who is affected by CVE-2026-18653?
CVE-2026-18653 affects WordPress installations running the WP Directory Kit plugin prior to version 1.5.7.
What can attackers achieve with CVE-2026-18653?
Attackers exploiting CVE-2026-18653 can execute SQL injection attacks potentially accessing sensitive data across the entire multisite network.