天下漏洞,尽知其名
MEDIUM

CVE-2026-16596 WordPress WP Directory Kit 插件 SQL 注入漏洞

影响认证攻击者可注入 SQL 查询,窃取数据库敏感信息

AI 研判

WP Directory Kit 是 WordPress 的一款目录/列表类插件。其 data_fields_list 参数未做充分转义,且 SQL 查询缺乏预处理,导致通用 SQL 注入。攻击者可借此拼接恶意 SQL 语句,读取数据库中的敏感数据。

影响范围

WP Directory Kit

影响 WP Directory Kit 插件 1.5.4 及之前的所有版本。

漏洞详情

漏洞类型为 SQL 注入,成因是插件对用户可控的 data_fields_list 参数转义不足,且构造 SQL 查询时未使用预处理语句。具备自定义级别及以上权限的认证用户可将额外 SQL 片段追加到原有查询中。攻击者据此可执行任意查询,从数据库中提取敏感信息。

利用条件与风险

利用需具备自定义级别及以上的认证账户权限,属于需登录的中危漏洞;一旦被利用可导致数据库信息泄露,实战中常被用于进一步渗透。

修复建议

官方已发布修复版本,建议升级至 1.5.4 之后的版本;暂无公开信息说明其他临时缓解措施,可先限制低权限账户访问相关功能。

原始情报

The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the ‘data_fields_list’ parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.