A vulnerability labeled as critical has been found in WP Directory Kit Plugin up to 1.5.4 on WordPress. The affected element is an unknown function. Executing a manipulation can lead to sql injection.

This vulnerability is registered as CVE-2026-18473. It is possible to launch the attack remotely. No exploit is available.

The affected component should be upgraded.