CVE 9.3 CRITICAL

WordPress WP Directory Kit plugin <= 1.5.1 - SQL Injection vulnerability_CVE-2026-42672

9.3 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection.

This issue affects WP Directory Kit: from n/a through 1.5.1.

AI Analysis

SQL Injection vulnerability in WP Directory Kit plugin

Basic Information

ID CVE-2026-42672
Source Patchstack
Published Jun 1, 2026 at 15:27

Affected Product

Vendor Wp Directory Kit
Product WP Directory Kit
Version n/a
Affected Versions Wp Directory Kit WP Directory Kit n/a

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor WordPress
Product WP Directory Kit
Version <= 1.5.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.