CVE-2024-3673 is a critical Local File Inclusion (LFI) vulnerability affecting the Web Directory Free WordPress plugin prior to version 1.7.3, allowing attackers to include arbitrary files due to improper input validation. With a CVSS score of 9.1, this vulnerability is easily exploitable over the network without user interaction, potentially leading to full data compromise and system availability impact. While not yet observed in active exploitation and not listed in CISA KEV, public Nuclei templates exist, indicating readily available exploit code. Despite its high EPSS and FAUCET risk scores, there is currently no significant community discussion or media coverage surrounding this flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.3CPE matchmatch criteria | cpe:2.3:a:salephpscripts:web_directory_free:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.