
CVE-2026-18230 The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX a… https://www.cve.org/CVERecord?id=CVE-2026-18230
Post summary
The WP Directory Kit WordPress plugin (before v1.5.6) contains a SQL injection flaw due to unsanitised AJAX parameters.
