
🚨*CVE* CVE-2026-18653 The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL… https://www.cve.org/CVERecord?id=CVE-2026-18653 ----- Traducción: CVE-2026-18653 El … https://infoflow.cloud`
Post summary
The post discloses that the WP Directory Kit WordPress plugin (versions prior to 1.5.7) is vulnerable to SQL injection, allowing administrators to execute arbitrary SQL.

