A vulnerability, which was classified as problematic, was found in WP Directory Kit Plugin up to 1.5.6 on WordPress. This issue affects some unknown processing. Executing a manipulation can lead to sql injection.
This vulnerability is registered as CVE-2026-18653. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.