CVE-2026-96653 | WP Directory Kit Plugin up to 1.5.9 on WordPress Profile Field update_listings_user_editor display_name sql injection

SecurityVulns

A vulnerability was found in WP Directory Kit Plugin up to 1.5.9 on WordPress. It has been rated as critical. This affects the function WdkCachedUserEditor::update_listings_user_editor of the component Profile Field. The manipulation of the argument display_name leads to sql injection.

This vulnerability is documented as CVE-2026-96653. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More