CVE-2026-16588: WP Directory Kit Plugin for WordPress Vulnerable to Blind SQL Injection
The WP Directory Kit plugin for WordPress is vulnerable to blind SQL injection via the 'order_by' parameter in versions up to 1.5.4. Authenticated attackers with custom-level access and above can exploit this flaw to extract sensitive information from the database. A CVSS score of 6.5 indicates a medium severity vulnerability.