CVE-2026-18473
WP Directory Kit SQL Injection Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
The WP Directory Kit WordPress plugin contains a critical SQL injection vulnerability that can be exploited by unauthenticated users. This flaw could allow attackers to access or modify sensitive data stored in the website's database. Given that WordPress sites are often publicly accessible, this issue warrants attenti