WordPress 插件 “WP Directory Kit”(版本 1.5.7 及更早)在将某些小工具(widget)设置值用于 SQL 语句时,未对其进行消毒(sanitize)和转义(escape)。这允许拥有页面构建器访问权限(权限等级为 Editor 或更高)的已认证用户执行 SQL 注入攻击,该攻击将在受影响页面被渲染时触发。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Directory Kit | 0 ~ 1.5.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16592 | WP Directory Kit <= 1.5.7 - Contributor+ Non-Public Listing Field Disclosure via Shortcode | |
| CVE-2026-18232 | WP Directory Kit <= 1.5.7 - Unauthenticated Unpublished Listing Disclosure via map_infowin |
No comments yet