CyberRota Analysis
AI-GeneratedThe WP Directory Kit versions up to 1.5.4 are vulnerable to an unauthenticated SQL injection, allowing attackers to manipulate database queries and potentially access sensitive information. This high-severity vulnerability poses a significant risk to any organization using this plugin, particularly those with exposed web applications. Administrators should prioritize patching or upgrading to mitigate the risk of exploitation.
CVE
CVE-2026-27538
Severity
HIGH
CVSS
7.5
EPSS
0.25%
Original NVD Description
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.