MEDIUM
CVE-2026-16593
CVSS
6.8
Description
The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.
Weakness (CWE)
CWE-89
SQL Injection
EPSS Score
0.23%
Probability of exploitation in next 30 days
14.1th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.