RULE(RULE ID:338439)

Rule General Information
Release Date: 2024-09-24
Rule Name: WordPress Plugin Web Directory Free 1.7.3 Local File Inclusion Vulnerability (CVE-2024-3673)
Severity:
CVE ID:
Rule Protection Details
Description: The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
Impact: When the file operation function in the application that does not filter the file path effectively, an attacker can import the path of a file which contains malicious code, causing a file inclusion vulnerability and executing malicious code.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.