DevSecOps Toolkit

CVE record

CVE-2026-39531

CRITICALCVSS 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.0.

Vulnerability metadata

Published
2026-05-21T10:46:23.030Z
Modified
2026-05-21T13:40:36.607Z
EPSS
Not available
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L

References