CVE-2024-3673
CRITICAL 9.1EPSS 5.6%
The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
- CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H - EPSS
- 5.58% chance of exploitation in the next 30 days, 92th percentile
- Nuclei
- critical
- Published
- 2024-08-30
Proof-of-concept exploits (3)
- https://wpscan.com/vulnerability/0e8930cb-e176-4406-a43f-a6032471debf/
- Nxploited/CVE-2024-36731★ · 2025-01-24
- tranphuc2005/Exploit_Wordpress0★ · 2025-07-02