CVE-2026-16596 Overview
CVE-2026-16596 is a SQL Injection vulnerability [CWE-89] affecting the WP Directory Kit plugin for WordPress. The flaw exists in all versions up to and including 1.5.4. It stems from insufficient escaping of the data_fields_list parameter and a lack of proper query preparation. Authenticated attackers holding custom-level access or higher can append additional SQL statements to existing queries. Successful exploitation allows extraction of sensitive information from the WordPress database, including credentials, session tokens, and personally identifiable information.
Critical Impact
Authenticated attackers with custom-level access can inject arbitrary SQL statements through the data_fields_list parameter, exposing confidential database contents.
Affected Products
- WP Directory Kit plugin for WordPress, versions up to and including 1.5.4
- WordPress sites permitting custom-level or higher user registration with the plugin active
- Any deployment using the vulnerable data_fields_list request parameter
Discovery Timeline
- 2026-09-30 - CVE-2026-16596 published to the National Vulnerability Database
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-16596
Vulnerability Analysis
The vulnerability resides in how the WP Directory Kit plugin handles the data_fields_list HTTP parameter. The plugin passes user-supplied input directly into a SQL query without proper escaping or parameterized statement preparation. This behavior maps to [CWE-89], Improper Neutralization of Special Elements used in a SQL Command.
Because the injection point is appended to an already-constructed query, attackers can use SQL stacking or UNION-based techniques to retrieve data outside the intended query scope. Sensitive tables such as wp_users and wp_usermeta become reachable, allowing extraction of password hashes, email addresses, and authentication metadata.
Exploitation requires an authenticated session with custom-level access or above. While this raises the bar over unauthenticated exploitation, WordPress deployments that permit self-registration or issue low-privilege accounts to external users remain exposed.
Root Cause
The plugin fails to apply wpdb::prepare() or equivalent sanitization functions such as esc_sql() to the data_fields_list parameter. The value is concatenated into the SQL statement string, so any SQL metacharacters submitted by the user are interpreted by the database engine.
Attack Vector
The attack vector is network-based. An authenticated attacker submits a crafted HTTP request containing malicious SQL fragments in the data_fields_list parameter. The plugin executes the tampered query against the WordPress database and returns results the attacker can observe or infer. Refer to the Wordfence Vulnerability Report and the WordPress Plugin Changeset for technical details.
Detection Methods for CVE-2026-16596
Indicators of Compromise
- HTTP requests containing SQL metacharacters such as UNION, SELECT, SLEEP(, or comment sequences (--, #) in the data_fields_list parameter
- Unexpected database queries in MySQL general or slow query logs referencing wp_users, wp_usermeta, or wp_options originating from plugin execution paths
- New or modified administrator accounts created shortly after suspicious plugin requests
Detection Strategies
- Deploy a Web Application Firewall (WAF) rule to inspect POST and GET parameters named data_fields_list for SQL syntax patterns
- Enable MySQL query logging and alert on UNION SELECT or time-based blind injection patterns issued through the plugin
- Audit WordPress access logs for authenticated low-privilege accounts issuing repetitive requests to WP Directory Kit endpoints
Monitoring Recommendations
- Correlate authentication events with anomalous parameter values to identify credential extraction attempts
- Monitor for outbound data exfiltration following successful injection, including large HTTP responses to authenticated users
- Track plugin version inventory across managed WordPress sites to flag installations at or below 1.5.4
How to Mitigate CVE-2026-16596
Immediate Actions Required
- Update the WP Directory Kit plugin to a version newer than 1.5.4 as soon as a fixed release is available
- Restrict custom-level and higher WordPress roles to trusted users and disable open registration where feasible
- Rotate WordPress administrator credentials and secret keys if exploitation is suspected
Patch Information
The upstream fix is tracked in the WordPress Plugin Changeset 3626960. Site owners should apply the patched plugin version through the WordPress admin dashboard or via WP-CLI. Review the Wordfence Vulnerability Report for advisory updates.
Workarounds
- Deactivate the WP Directory Kit plugin until the site can be upgraded to a fixed release
- Deploy a WAF ruleset that blocks SQL metacharacters in the data_fields_list parameter
- Revoke custom-level access from untrusted accounts and enforce the principle of least privilege on WordPress roles
# Configuration example: update the WP Directory Kit plugin via WP-CLI
wp plugin update wp-directorykit --version=<patched_version>
wp plugin list --name=wp-directorykit --fields=name,status,version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
