GHSA-vj8p-cr6v-v7p3MediumCVSS 6.8

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget...

Published
September 15, 2026
Last Modified
September 15, 2026

🔗 CVE IDs covered (1)

📋 Description

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.

🔗 References (3)