MEDIUM
wpdirectorykit
CVE published 2026-10-10
CVE-2026-96653
The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via the 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9. This is because of insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. Authenticated attackers with subscriber-level access and above can append additional SQL quer [truncated]