CVE-2024-3673: Salephpscripts Web Directory Free

Critical severity, CVSS 9.1. EPSS: 5.6% chance of exploitation in the next 30 days.

The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.

Affected products

Published 2024-08-30. Last modified 2026-06-17.