Sceawere

Vulnerability Detail

CVE-2026-16596UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Directory Kit SQL Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
wpdirectorykit
Product
WP Directory Kit
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-30T08:16:32.987Z",
  "pubdate": "2026-09-30T08:16:32.987Z",
  "executiveSummary": "The WP Directory Kit plugin for WordPress contains a critical SQL Injection vulnerability present in all versions up to and including 1.5.4.\nThe vulnerability arises from improper neutralization of user-supplied data within the 'data_fields_list' parameter, which is subsequently processed by database queries without sufficient sanitization or the use of prepared statements.\nAn attacker with custom-level access or higher can exploit this flaw to execute arbitrary SQL commands against the underlying database.\nThe impact of this vulnerability is severe, allowing unauthorized actors to perform unauthorized database operations, including the exfiltration of sensitive information, modification of application data, or potential elevation of privileges within the WordPress environment.\nSuccessful exploitation requires authenticated access to the target WordPress installation, specifically targeting accounts with privileges sufficient to interact with the vulnerable plugin functionality.\nThis vulnerability highlights a significant risk of data breach and database integrity compromise, necessitating immediate attention to patching or limiting access to affected components.",
  "technicalDetails": "The vulnerability is identified as a generic SQL Injection (SQLi) flaw located within the handling of the 'data_fields_list' parameter in the WP Directory Kit plugin.\nRoot Cause Analysis: The application fails to implement robust input validation or parameterized queries (prepared statements) when constructing database queries involving the 'data_fields_list' parameter. Because the plugin incorporates user-controlled input directly into the SQL statement, the database engine cannot distinguish between developer-intended SQL commands and data manipulated by an attacker.\nAttack Flow: An authenticated attacker possessing custom-level privileges or higher can submit a crafted HTTP request containing a malicious payload via the 'data_fields_list' parameter. Since the plugin does not properly escape these inputs, the malicious SQL syntax is concatenated into the existing query structure.\nExploitation Method: By injecting SQL control characters (such as single quotes, semicolons, or comment indicators), an attacker can break out of the original query context. This allows for the chaining of additional SQL queries (stacked queries) or the modification of the original query logic using UNION-based techniques.\nPayload Behavior: Upon receipt of the malicious payload, the backend database executes the injected commands. Depending on the database configuration and permissions, this can lead to unauthorized data retrieval from arbitrary tables, including wp_users, configuration settings, or private metadata.\nAffected Versions and Components: All versions of the WP Directory Kit plugin up to and including 1.5.4 are affected. The vulnerability exists within the logic responsible for processing 'data_fields_list', making this a component-level defect in query execution handling.\nPost-Exploitation Impact: Beyond the initial exfiltration of sensitive data, an attacker may leverage this vulnerability to dump the database schema, bypass authentication mechanisms, or gain further administrative control over the WordPress application by modifying user roles or injecting administrative accounts.\nEnvironment Requirements: This exploit is limited to authenticated users; however, the 'custom-level access' requirement effectively widens the attack surface to any user role with standard interaction capabilities defined by the plugin's permissions model. The vulnerability is exploitable over the network through standard HTTP/HTTPS request vectors."
}
CVE-2026-16596: WP Directory Kit SQL Injection (MEDIUM Severity, CVSS: 6.5) | Sceawere