PatchSiren

wpdirectorykit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wpdirectorykit CVE published 2026-10-10

CVE-2026-96653

The WP Directory Kit plugin for WordPress is vulnerable to time-based SQL Injection via the 'display_name' Profile Field (Second-Order) in all versions up to, and including, 1.5.9. This is because of insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. Authenticated attackers with subscriber-level access and above can append additional SQL quer [truncated]