
CVE-2026-18474 The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable… https://www.cve.org/CVERecord?id=CVE-2026-18474
Post summary
The text announces a SQL injection vulnerability in WP Directory Kit versions prior to 1.5.6, noting that the plugin fails to sanitise inputs before use in SQL statements; no exploitation proof‑of‑concepts, patches, or active exploitation claims are provided.
