What is CVE-2026-18230?
This CVE describes an SQL injection vulnerability in the WP Directory Kit plugin. Any authenticated user, such as a Subscriber, can exploit an AJAX action lacking authorization and proper input sanitization to interfere with the database. Users must update to version 1.5.6 immediately.
Azərbaycanca: Bu CVE, WP Directory Kit plaginindəki SQL injection zəifliyidir. İstənilən autentifikasiya olunmuş istifadəçi (məsələn, abunəçi) müəyyən AJAX əməliyyatı vasitəsilə verilənlər bazasına müdaxilə edə bilər, çünki parametr təmizlənmir. Plagindən istifadə edənlər dərhal 1.5.6 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What security risk does CVE-2026-18230 pose for the WP Directory Kit plugin?
This CVE describes an SQL injection vulnerability in the WP Directory Kit plugin. Any authenticated user, such as a Subscriber, can exploit an AJAX action lacking proper input sanitization to interfere with the database.
To which version should WP Directory Kit users update to protect against CVE-2026-18230?
Users must update to version 1.5.6 of the WP Directory Kit plugin immediately to protect against this SQL injection vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.