CVE-2026-42672
A security flaw in the Wp Directory Kit plugin allows attackers to perform a 'Blind SQL Injection.' This means an attacker can send malicious commands to the database that the application processes improperly.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of the Wp Directory Kit plugin, specifically versions from the beginning of its release through version 1.5.1.
Real-world impact
An attacker could potentially access, modify, or delete sensitive information stored in the website's database by tricking the software into executing unauthorized commands.
Why this severity
This vulnerability is rated as critical because it can be exploited remotely over the internet without needing any special permissions or user interaction, potentially leading to a total compromise of database confidentiality.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 1, 2026 · Jun 1, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.