CVE-2026-18653

WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter

The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before using it in a SQL statement, allowing administrators to perform SQL injection attacks. On a multisite installation this lets an administrator of a single site read data belonging to the entire network, which they are not otherwise able to reach.


We have discovered 209 live websites that are affected by CVE-2026-18653.

Run a Free Instant Scan




Affected Software

Product  Wpdirectorykit
Category Wordpress Plugins
Vulnerable Domains209 live websites (100% of Wpdirectorykit install base)
Vulnerable Versions
  • from 0 through 1.5.7
Vulnerable Versions Count16 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 16, 2026
  • Updated - Aug 17, 2026

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18653
United States66 websites



Italy21 websites
Germany18 websites
Netherlands8 websites
GB7 websites
India7 websites
Spain7 websites
Cyprus6 websites
France6 websites
Argentina5 websites

Website Distribution by TLD

Number of websites using CVE-2026-18653
.com102 websites
.it15 websites
.org7 websites
.de7 websites
.nl5 websites
.com.br5 websites
.net4 websites
.es4 websites
.com.au3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18653

Top websites that are affected by CVE-2026-18653. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States***,***
***************.org United States***,***
************************.com Germany*,***,***
***************.com United States*,***,***
*****.nl Netherlands*,***,***
************.com United States*,***,***
******.net United States*,***,***
************.com GB*,***,***
*******************.***.au Australia*,***,***
*********.org United States*,***,***
See full domain list

FAQ

CVE-2026-18653 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Wpdirectorykit
A total of 209 websites have been identified as vulnerable to CVE-2026-18653, based on global website indexing conducted by WebTechSurvey.
The Wpdirectorykit is affected by the CVE-2026-18653 vulnerability.
Wpdirectorykit versions up to 1.5.7 are vulnerable to CVE-2026-18653.
CVE-2026-18653 is resolved in version 1.5.7 of Wpdirectorykit.