CVE-2024-3673: Salephpscripts Web Directory Free
Critical severity, CVSS 9.1. EPSS: 5.6% chance of exploitation in the next 30 days.
The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
Affected products
- Salephpscripts Web Directory Free: before 1.7.3 (fixed in 1.7.3)
Published 2024-08-30. Last modified 2026-06-17.