Sceawere
Vulnerability Detail
CVE-2026-96653UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Directory Kit SQL Injection
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 2h ago
- Vendor
- wpdirectorykit
- Product
- WP Directory Kit
- Attack Type
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order injection: a Subscriber stores a display_name containing a single quote via their own profile, which WordPress preserves verbatim; the payload is then triggered when WdkCachedUserEditor::update_listings_user_editor() re-reads that stored value and passes it unsanitized to the SQL sink.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-10T08:17:07.843Z",
"pubdate": "2026-10-10T08:17:07.843Z",
"executiveSummary": "The WP Directory Kit plugin for WordPress contains a critical second-order time-based SQL Injection vulnerability affecting all versions up to and including 1.5.9.\nThe vulnerability originates from insufficient input sanitization and inadequate SQL query preparation when handling user-defined profile fields.\nAn authenticated attacker with subscriber-level privileges or higher can store a malicious payload within the 'display_name' profile field.\nThis payload remains dormant until the application processes the stored data, at which point it triggers an unauthorized SQL query execution.\nSuccessful exploitation allows an attacker to append arbitrary SQL commands to the existing query structure, facilitating unauthorized data extraction and potential database compromise.\nGiven that this vulnerability requires authenticated access but bypasses standard input validation, it represents a significant security risk to the integrity and confidentiality of the WordPress database.",
"technicalDetails": "The vulnerability is identified as a second-order SQL Injection (SQLi) within the WP Directory Kit plugin. The root cause is the improper handling of user-supplied data during both the storage phase and the subsequent retrieval/processing phase within the application.\nSpecifically, the 'display_name' profile field fails to undergo rigorous sanitization before being saved into the WordPress database. Because WordPress preserves this data verbatim, an attacker can supply a specially crafted string containing SQL injection characters, such as a single quote, which terminates the intended string literal context in a later database operation.\nThe vulnerability is triggered by the WdkCachedUserEditor::update_listings_user_editor() function. When this function re-reads the previously stored 'display_name' value, it passes the unsanitized input directly into an SQL query sink without utilizing parameterized queries or appropriate escaping mechanisms.\nThe attack flow follows a predictable pattern: 1) The attacker updates their user profile, injecting a time-based SQL payload (e.g., using SLEEP() or BENCHMARK() functions) into the 'display_name' field. 2) The system stores this malicious string in the database. 3) The WdkCachedUserEditor::update_listings_user_editor() function is later invoked, either via an administrative action or a scheduled task, which retrieves the attacker-controlled input.\nBecause the function fails to prepare the SQL statement, the injected payload alters the query logic. The 'time-based' nature of this injection allows an attacker to infer data from the database by observing the time delay in the server's HTTP response, confirming successful execution even if direct output is not reflected in the UI.\nThis vulnerability is particularly dangerous because it bypasses conventional perimeter defenses that might only scan for immediate, first-order injection attempts. The impact is severe, potentially allowing for unauthorized data exfiltration, information disclosure, and potentially escalated database-level attacks depending on the permissions of the database user account utilized by the WordPress installation.\nThe flaw affects all versions up to and including 1.5.9. Exploitation requires at least subscriber-level authentication, making it accessible to any registered user on a site with open registration enabled."
}