Description
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Published: 2026-08-13
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated SQL injection flaw that allows an attacker to execute arbitrary SQL statements against the database used by the WordPress Web Directory Free plugin. If exploited, the attacker can read, modify, or delete data, and potentially pivot to more privileged operations, leading to data loss, defacement, or further compromise of the site.

Affected Systems

The affected product is the WordPress Web Directory Free plugin developed by Shamalli, versions 1.7.13 and earlier.

Risk and Exploitability

The CVSS score of 9.3 identifies this flaw as critical. EPSS information is not available, but the lack of a KEV listing does not reduce the risk for existing users. The exploit requires only an unauthenticated HTTP request to the plugin’s endpoint, so the attack vector is remote via the web interface. Successful exploitation can grant an attacker persistent access to the database, resulting in data exfiltration and the possibility of further attacks.

Generated by OpenCVE AI on August 13, 2026 at 16:35 UTC.

Remediation

Vendor Solution

Update the WordPress Web Directory Free plugin to the latest available version (at least 2.0).


OpenCVE Recommended Actions

  • Update the Web Directory Free plugin to version 2.0 or later, which patches the SQL injection flaw.
  • If a quick upgrade is not feasible, disable or uninstall the plugin until the patch can be applied to eliminate the attack surface.
  • As an interim control, restrict access to the plugin’s URLs using a web‑application firewall or network firewall rules to block unauthenticated requests.

Generated by OpenCVE AI on August 13, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Shamalli
Shamalli web Directory Free
Wordpress
Wordpress wordpress
Vendors & Products Shamalli
Shamalli web Directory Free
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Title WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Shamalli Web Directory Free
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:23:29.723Z

Reserved: 2026-02-25T12:14:18.579Z

Link: CVE-2026-28142

cve-icon Vulnrichment

Updated: 2026-08-13T15:23:19.768Z

cve-icon NVD

Status : Received

Published: 2026-08-13T14:16:57.813

Modified: 2026-08-13T16:18:02.263

Link: CVE-2026-28142

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:00:10Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')