Vulnerability Description
The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL injection attacks that execute when the affected page is rendered.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-16593?
CVE-2026-16593 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder...
How severe is CVE-2026-16593?
CVE-2026-16593 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-16593?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.