SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18653

HIGH · CVSS 7.2 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The WP Directory Kit plugin for WordPress prior to version 1.5.7 is vulnerable to SQL injection due to insufficient sanitization and escaping of parameters in SQL statements. This flaw allows an administrator of a single site within a multisite installation to access and read sensitive data from the entire network, posing a significant risk to data confidentiality. WordPress administrators, especially those managing multisite environments, should prioritize updating this plugin to mitigate potential exploitation.

CVE
CVE-2026-18653
Severity
HIGH
CVSS
7.2
EPSS
0.31%
WordPress

Original NVD Description

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach.