CVE-2026-66649: WordPress Directory Pro plugin <= 2.5.8 - SQL Injection vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
Affected Software
1 affected component
WordPress Directory Pro<=2.5.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Directory Proto a version that resolves this vulnerability.Fixed in 2.5.8
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need a WordPress account or user interaction to exploit this issue?
No. The vulnerability is rated as remotely exploitable without privileges or user interaction, and is described as unauthenticated.
2
What is the expected security impact if exploitation succeeds?
The supplied vector indicates high confidentiality impact and low availability impact. It indicates no integrity impact.
3
Which plugin versions are identified as affected?
Directory Pro versions 2.5.8 and earlier are identified as affected.