Executive brief
The Web Directory Free plugin for WordPress, which is used to create business directories and listings, contains a security flaw that allows unauthorized individuals to access sensitive information. By sending a specially crafted request, an attacker can bypass security measures to view private data stored in the website's database. This could lead to the exposure of user information or other confidential site data.
Technical details
The Web Directory Free plugin for WordPress is vulnerable to a generic SQL injection vulnerability due to improper neutralization of the 'levels' parameter. The flaw exists in the ajax_controller.php and frontend_controller.php files where user-supplied input is concatenated into SQL queries without sufficient escaping or use of prepared statements. An unauthenticated remote attacker can exploit this by sending malicious SQL commands via the 'levels' parameter to extract sensitive data from the database. All versions up to and including 1.7.13 are affected.
Affected products
- mihail-chepovskiy Web Directory Free up to, and including, 1.7.13
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
References
- https://plugins.trac.wordpress.org/browser/web-directory-free/tags/1.7.13/classes/ajax_controller.php
- https://plugins.trac.wordpress.org/browser/web-directory-free/tags/1.7.13/classes/frontend_controller.php
- https://plugins.trac.wordpress.org/browser/web-directory-free/tags/1.7.13/classes/frontend_controller.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7320421b-6b88-452d-a363-a71cdf7953a6?source=cve