CVE-2026-18474

WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.


We have discovered 207 live websites that are affected by CVE-2026-18474.

Run a Free Instant Scan




Affected Software

Product  Wpdirectorykit
Category Wordpress Plugins
Vulnerable Domains207 live websites (100% of Wpdirectorykit install base)
Vulnerable Versions
  • from 0 through 1.5.6
Vulnerable Versions Count15 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Pedro Pinho (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18474
United States64 websites



Italy21 websites
Germany18 websites
Netherlands8 websites
GB7 websites
India7 websites
Spain7 websites
Cyprus6 websites
France6 websites
Argentina5 websites

Website Distribution by TLD

Number of websites using CVE-2026-18474
.com102 websites
.it15 websites
.de7 websites
.org6 websites
.nl5 websites
.com.br5 websites
.es4 websites
.net3 websites
.com.au3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18474

Top websites that are affected by CVE-2026-18474. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States***,***
************************.com Germany*,***,***
***************.com United States*,***,***
*****.nl Netherlands*,***,***
************.com United States*,***,***
************.com GB*,***,***
*******************.***.au Australia*,***,***
*********.org United States*,***,***
*******************.com Mexico*,***,***
****.ch Switzerland**,***,***
See full domain list

FAQ

CVE-2026-18474 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Wpdirectorykit
A total of 207 websites have been identified as vulnerable to CVE-2026-18474, based on global website indexing conducted by WebTechSurvey.
The Wpdirectorykit is affected by the CVE-2026-18474 vulnerability.
Wpdirectorykit versions up to 1.5.6 are vulnerable to CVE-2026-18474.
CVE-2026-18474 is resolved in version 1.5.6 of Wpdirectorykit.