← WordPress Vulnerabilities
WordPress security by component

Web Directory Free

Web Directory Free is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: web-directory-free

CVE-2026-14785: Web Directory Free exposes unauthenticated SQL injection through listing levels

Web Directory Free through 1.7.13 registers the public w2dc_controller_request AJAX action. A request to /wp-admin/admin-ajax.php with action=w2dc_controller_request copies attacker-controlled POST values into shortcode attributes; supplying levels as an array bypasses wp_parse_id_list(), receives only trim(), and reaches w2dc_frontend_controller::where_levels_ids(), which concatenates the values into the w2dc_levels.id IN (...) SQL clause. An unauthenticated attacker can consequently alter the query and extract sensitive database information. No fixed public release is identified, and the WordPress.org plugin entry is closed.

PublishedJul 28, 2026
Safe version guidanceSee mitigation notes
Safe version
Jul 28, 2026 CVE-2026-14785
Web Directory Free exposes unauthenticated SQL injection through listing levels
Web Directory Free through 1.7.13 registers the public w2dc_controller_request AJAX action. A request to /wp-admin/admin-ajax.php with action=w2dc_controller_request copies attacker-controlled POST values into shortcode attributes; supplying levels as an array bypasses wp_parse_id_list(), receives only trim(), and reaches w2dc_frontend_controller::where_levels_ids(), which concatenates the values into the w2dc_levels.id IN (...) SQL clause. An unauthenticated attacker can consequently alter the query and extract sensitive database information. No fixed public release is identified, and the WordPress.org plugin entry is closed.
See mitigation notes
CVE7.5
NVDPending
Dec 30, 2025 CVE-2025-69018
Web Directory Free: Cross-site scripting
Web Directory Free is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Apr 17, 2025 CVE-2025-39567
Web Directory Free: Cross-site scripting
Web Directory Free is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Apr 03, 2025 CVE-2025-30908
Web Directory Free: Cross-site scripting
Web Directory Free is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Mar 25, 2025 CVE-2025-28904
Web Directory Free: SQL injection
Web Directory Free is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.3
NVDPending
Oct 05, 2024 CVE-2024-47379
Web Directory Free: Cross-site scripting
Web Directory Free is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Aug 30, 2024 CVE-2024-3673
Web Directory Free: Filesystem traversal
Web Directory Free is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE9.1
NVDPending
Jul 30, 2024 CVE-2024-3669
Web Directory Free: Cross-site scripting
Web Directory Free is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.8
NVDPending
Jun 13, 2024 CVE-2024-3552
Web Directory Free: SQL injection
Web Directory Free is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Jun 02, 2023 CVE-2023-2201
Web Directory Free: SQL injection
Web Directory Free is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8