CVE-2026-16593
Received Received - Intake

SQL Injection in WP Directory Kit WordPress Plugin

Vulnerability report for CVE-2026-16593, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: WPScan

Description

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_directory_kit wp_directory_kit to 1.5.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a SQL injection flaw in the WP Directory Kit WordPress plugin versions 1.5.7 and below. It occurs in the Elementor Category and Location Widget Settings, where unsanitized input is used directly in SQL queries. Authenticated users with Editor or higher privileges can exploit this to inject malicious SQL code.

Detection Guidance

Check if the WP Directory Kit plugin version 1.5.7 or below is installed. Log in as an Editor or higher user and inspect widget settings for unsanitized SQL inputs. Monitor database queries for unexpected patterns or errors.

Impact Analysis

If you are an administrator or user with Editor privileges on a WordPress site using the affected plugin, an attacker with similar access could manipulate your database. This may lead to unauthorized data access, modification, or deletion. Regular users without Editor access cannot exploit this vulnerability.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, which may violate compliance requirements under GDPR or HIPAA. Organizations using this plugin must address it promptly to avoid potential legal and regulatory penalties.

Mitigation Strategies

Update the WP Directory Kit plugin to the latest version immediately. Remove or disable the plugin if an update is unavailable. Restrict Editor and higher user roles to minimize exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16593. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart