Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.8.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs because the Web Directory Free plugin does not properly neutralize user‑supplied input before inserting it into a web page. When an attacker places malicious script code in a query parameter, the plugin echoes it back unescaped, allowing reflected cross‑site scripting. The weakness is classic input validation failure, classified as CWE‑79. If a victim follows a crafted URL, arbitrary JavaScript can execute in their browser, potentially compromising that session. The effect is confined to the victim’s browser session and depends on the user visiting the malicious link.

Affected Systems

WordPress sites that include the Shamalli Web Directory Free plugin of version 1.7.8 or earlier are affected. Any installation that has not been upgraded beyond the stated maximum version remains vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity, and the EPSS score of less than 1% shows that exploitation opportunities have been observed but are currently rare. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by sending a crafted URL containing the malicious payload to a legitimate user; upon visiting, the script runs in the user’s browser. The low EPSS suggests that the risk of widespread exploitation is currently small, but the potential impact warrants timely remediation.

Generated by OpenCVE AI on May 1, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Web Directory Free plugin to the latest available release, which removes the unsanitized input handling.
  • If an immediate upgrade is not possible, use a web application firewall or server‑side filtering to block or sanitize the query parameter that is reflected in the output.
  • Deploy a Content Security Policy that disallows inline scripts and limits script execution to trusted sources, reducing the effectiveness of any residual XSS payloads.

Generated by OpenCVE AI on May 1, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11750 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free allows Reflected XSS. This issue affects Web Directory Free: from n/a through 1.7.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free allows Reflected XSS. This issue affects Web Directory Free: from n/a through 1.7.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free web-directory-free allows Reflected XSS.This issue affects Web Directory Free: from n/a through <= 1.7.8.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shamalli Web Directory Free allows Reflected XSS. This issue affects Web Directory Free: from n/a through 1.7.8.
Title WordPress Web Directory Free plugin <= 1.7.8 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:34.877Z

Reserved: 2025-04-16T06:25:01.732Z

Link: CVE-2025-39567

cve-icon Vulnrichment

Updated: 2025-04-17T18:09:23.606Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:58.050

Modified: 2026-04-23T15:29:48.187

Link: CVE-2025-39567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T10:00:12Z

Weaknesses