Executive brief
Webilia Listdom, a WordPress plugin used for creating directory and listing websites, contains a critical security flaw. This vulnerability allows an attacker to interact directly with the website's database without needing a password. An exploit could lead to the theft of sensitive customer data or internal site information, potentially impacting the organization's reputation and data privacy compliance.
Technical details
A Blind SQL Injection vulnerability exists in the Webilia Inc. Listdom plugin for WordPress (versions up to and including 5.4.0) due to improper neutralization of special elements in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries against the backend database. Because it is a 'blind' injection, attackers can infer data by observing differences in application responses or timing. This can lead to full database extraction. The issue is resolved in version 5.5.0.
Affected products
- Webilia Inc. Listdom n/a through 5.4.0
Timeline
- 2026-04-24: other: Vulnerability reported by researcher Evan NR
- 2026-06-17: advisory: Advisory published by Patchstack and NVD
- 2026-06-17: patched: Patch released in version 5.5.0