CVE-2026-28001

WordPress WP Directory Kit plugin <= 1.5.4 - SQL Injection vulnerability

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.


We have discovered 206 live websites that are affected by CVE-2026-28001.

Run a Free Instant Scan




Affected Software

Product  Wpdirectorykit
Category Wordpress Plugins
Vulnerable Domains206 live websites (100% of Wpdirectorykit install base)
Vulnerable Versions
  • from 0 through 1.5.4
Vulnerable Versions Count15 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • Jayant Kamble | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-28001
United States64 websites



Italy21 websites
Germany18 websites
Netherlands8 websites
GB7 websites
India7 websites
Spain7 websites
Cyprus6 websites
France6 websites
Argentina5 websites

Website Distribution by TLD

Number of websites using CVE-2026-28001
.com102 websites
.it15 websites
.de7 websites
.org6 websites
.nl5 websites
.com.br5 websites
.es4 websites
.net3 websites
.com.au3 websites
.eu3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-28001

Top websites that are affected by CVE-2026-28001. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.com United States***,***
************************.com Germany*,***,***
***************.com United States*,***,***
*****.nl Netherlands*,***,***
************.com United States*,***,***
************.com GB*,***,***
*******************.***.au Australia*,***,***
*********.org United States*,***,***
*******************.com Mexico*,***,***
****.ch Switzerland**,***,***
See full domain list

FAQ

CVE-2026-28001 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Wpdirectorykit
A total of 206 websites have been identified as vulnerable to CVE-2026-28001, based on global website indexing conducted by WebTechSurvey.
The Wpdirectorykit is affected by the CVE-2026-28001 vulnerability.
Wpdirectorykit versions up to and including 1.5.4 are vulnerable to CVE-2026-28001.