These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach. The vulnerability is caused by a lack of input sanitisation and [truncated]
The WP Directory Kit WordPress plugin before 1.5.5 is vulnerable to SQL injection. This vulnerability is exploitable by unauthenticated users and could lead to significant impact on affected systems. Users should verify their deployments and check for vendor remediation. The CVE record was published on 2026-08-09T06:19:05.773Z and has not been modified since then. However, the full extent of the vulnerabi [truncated]
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the site's user list and unpublished listings belonging to other users. This vulnerability allows an attacker to potentially access sensitive information, including the site's user list and unpublished l [truncated]
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to disclose the WP Directory Kit WordPress plugin before 1.5.5 settings including sensitive API keys and secrets. This vulnerability affects users of the WP Directory Kit WordPress plugin, especially those with sens [truncated]
The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing any authenticated user such as a Subscriber to retrieve stored contact messages and associated user data belonging to other users. This vulnerability has significant implications for the security and privacy of affected systems, as it could allow unauthorized [truncated]
CVE-2026-39534 is a HIGH severity vulnerability (CVSS Score: 7.5) in the WP Directory Kit plugin versions <= 1.5.0. The vulnerability is caused by unauthenticated broken access control. The CVE was published on [cvePublishedAt]2026-06-15T21:16:47.310Z[/cvePublishedAt] and last modified on [cveModifiedAt]2026-06-15T21:24:32.790Z[/cveModifiedAt]. For more information, refer to the [resourceLinkAnnotations i [truncated]
A critical blind SQL injection vulnerability exists in the WP Directory Kit WordPress plugin, affecting versions up to and including 1.5.1. The vulnerability stems from improper neutralization of special elements in SQL commands (CWE-89), allowing unauthenticated attackers to manipulate database queries. With a CVSS 3.1 score of 9.3, this vulnerability presents severe risk due to network attack vector, lo [truncated]
CVE-2026-39531 is a critical blind SQL injection issue affecting the WP Directory Kit plugin through version 1.5.0. The vulnerability was published on 2026-05-21 and has a CVSS 3.1 score of 9.3, with NVD listing the record as Deferred. Because the supplied source attribution is incomplete, the vendor identity should be treated carefully and validated against the linked Patchstack reference before making o [truncated]