What is CVE-2026-18473?
CVE-2026-18473 is a critical SQL injection (SQLi) vulnerability in the WP Directory Kit WordPress plugin versions prior to 1.5.5. Due to improper sanitization of a parameter, unauthenticated users can execute malicious SQL statements. It is imperative to update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-18473, WordPress WP Directory Kit plagininin 1.5.5-dən əvvəlki versiyalarında aşkarlanmış kritik SQL injection (SQLi) zəifliyidir. Plagin parametrləri düzgün təmizləmədiyi üçün autentifikasiya olunmamış istifadəçilər verilənlər bazasına müdaxilə edə bilər. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WP Directory Kit plugin are affected by CVE-2026-18473?
The vulnerability affects all versions of the WP Directory Kit plugin prior to 1.5.5.
Is authentication required to exploit CVE-2026-18473?
No, this critical SQL injection vulnerability can be exploited by unauthenticated users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.