Impact
The vulnerability is an unauthenticated SQL injection flaw that allows an attacker to execute arbitrary SQL statements against the database used by the WordPress Web Directory Free plugin. If exploited, the attacker can read, modify, or delete data, and potentially pivot to more privileged operations, leading to data loss, defacement, or further compromise of the site.
Affected Systems
The affected product is the WordPress Web Directory Free plugin developed by Shamalli, versions 1.7.13 and earlier.
Risk and Exploitability
The CVSS score of 9.3 identifies this flaw as critical. EPSS information is not available, but the lack of a KEV listing does not reduce the risk for existing users. The exploit requires only an unauthenticated HTTP request to the plugin’s endpoint, so the attack vector is remote via the web interface. Successful exploitation can grant an attacker persistent access to the database, resulting in data exfiltration and the possibility of further attacks.
OpenCVE Enrichment