AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-27538

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Directory Kit versions up to 1.5.4 are vulnerable to an unauthenticated SQL injection, allowing attackers to manipulate database queries and potentially access sensitive information. This high-severity vulnerability poses a significant risk to any organization using this plugin, particularly those with exposed web applications. Administrators should prioritize patching or upgrading to mitigate the risk of exploitation.

CVE
CVE-2026-27538
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.