A vulnerability has been found in WP Directory Kit Plugin up to 1.5.1 on WordPress and classified as critical. This affects an unknown part. This manipulation causes sql injection.

The identification of this vulnerability is CVE-2026-42672. It is possible to initiate the attack remotely. There is no exploit available.