sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total31
Critical4
High12
Medium14
Reset
Showing 1-20 of 31 records
Threat Entry Updated 2026-09-17

WP Directory Kit - Security Vulnerability (CVE-2026-16588)

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN WP Directory Kit

CVE-2026-16588

MEDIUM CVSS 6.5 2026-09-16
Threat Entry Updated 2026-08-26

WP Directory Kit - Security Vulnerability (CVE-2026-18231)

The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered database rows, allowing unauthenticated attackers to retrieve the usernames and email addresses of users holding the WP Directory Kit WordPress plugin before 1.5.7's own roles.

PLUGIN WP Directory Kit

CVE-2026-18231

MEDIUM CVSS 5.3 2026-08-19
Threat Entry Updated 2026-08-26

WP Directory Kit - SQL Injection (CVE-2026-18653)

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach.

PLUGIN WP Directory Kit

CVE-2026-18653

HIGH CVSS 7.2 2026-08-16
Threat Entry Updated 2026-08-26

WP Directory Kit - SQL Injection (CVE-2026-18474)

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.

PLUGIN WP Directory Kit

CVE-2026-18474

HIGH CVSS 8.6 2026-08-12
Threat Entry Updated 2026-08-26

WP Directory Kit - SQL Injection (CVE-2026-18230)

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.

PLUGIN WP Directory Kit

CVE-2026-18230

HIGH CVSS 8.1 2026-08-12
Threat Entry Updated 2026-08-26

WP Directory Kit - SQL Injection (CVE-2026-18473)

The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

PLUGIN WP Directory Kit

CVE-2026-18473

CRITICAL CVSS 9.1 2026-08-09
Threat Entry Updated 2026-08-26

WP Directory Kit - SQL Injection (CVE-2026-16589)

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks authorization and nonce checks, allowing any authenticated user such as a Subscriber to perform SQL injection attacks.

PLUGIN WP Directory Kit

CVE-2026-16589

HIGH CVSS 7.7 2026-08-08
Threat Entry Updated 2026-08-26

WP Directory Kit - Cross-Site Request Forgery (CSRF) (CVE-2026-16594)

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets.

PLUGIN WP Directory Kit

CVE-2026-16594

HIGH CVSS 7.5 2026-08-08
Threat Entry Updated 2026-08-26

WP Directory Kit - Cross-Site Request Forgery (CSRF) (CVE-2026-16590)

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users.

PLUGIN WP Directory Kit

CVE-2026-16590

MEDIUM CVSS 6.5 2026-08-08
Threat Entry Updated 2026-06-17

WP Directory Kit - Information Disclosure (CVE-2025-13920)

The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.9 via the wdk_public_action AJAX handler. This makes it possible for unauthenticated attackers to extract email addresses for users with Directory Kit-specific user roles.

PLUGIN WP Directory Kit

CVE-2025-13920

MEDIUM CVSS 5.3 2026-01-24
Threat Entry Updated 2026-06-17

WP Directory Kit - SQL Injection (CVE-2025-13089)

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' parameter in all versions up to, and including, 1.4.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN WP Directory Kit

CVE-2025-13089

HIGH CVSS 7.5 2025-12-13
Threat Entry Updated 2026-06-17

Wp Directory Kit - Authentication Bypass (CVE-2025-13390)

The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.

PLUGIN Wp Directory Kit

CVE-2025-13390

CRITICAL CVSS 10.0 2025-12-03
Threat Entry Updated 2026-06-17

WP Directory Kit - SQL Injection (CVE-2025-13090)

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 1.4.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN WP Directory Kit

CVE-2025-13090

MEDIUM CVSS 4.9 2025-12-02
Threat Entry Updated 2026-06-17

WP Directory Kit - Cross-Site Scripting (XSS) (CVE-2025-13525)

The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter in all versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

PLUGIN WP Directory Kit

CVE-2025-13525

MEDIUM CVSS 6.1 2025-11-27
Threat Entry Updated 2026-06-17

WP Directory Kit - SQL Injection (CVE-2025-13138)

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the select_2_ajax() function in all versions up to, and including, 1.4.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

PLUGIN WP Directory Kit

CVE-2025-13138

HIGH CVSS 7.5 2025-11-21