← Back to browse · API

CVE-2024-3552

Severity
CRITICAL
CVSS
9.8
EPSS
0.67288
Risk score
62.75
CISA KEV
No
PoC
No
Published
2024-06-13
Modified
2025-03-25
First seen
2026-08-07
Aliases
EUVD-2024-32138, GHSA-JWG5-QQGR-9462
Products
Shamalli:Web Directory Free 0 <1.7.0
Sources
euvd EUVD-2024-32138

Description

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.

References