A vulnerability was found in WP Directory Kit Plugin up to 1.5.5 on WordPress. It has been declared as critical. Impacted is an unknown function. Executing a manipulation can lead to sql injection.

The identification of this vulnerability is CVE-2026-18230. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.