CVE-2026-28142: WordPress Web Directory Free plugin <= 1.7.13 - SQL Injection vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.
Affected Software
1 affected component
WordPress Web Directory Free<=1.7.13
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Web Directory Freeto a version that resolves this vulnerability.Fixed in 2.0
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28142?
CVE-2026-28142 has a critical severity rating of 9.3.
2
What kind of vulnerability is CVE-2026-28142?
CVE-2026-28142 is an unauthenticated SQL Injection vulnerability found in the Web Directory Free plugin for WordPress.
3
How do I fix CVE-2026-28142?
To mitigate CVE-2026-28142, update the Web Directory Free plugin to version 1.7.14 or later.
4
What versions are affected by CVE-2026-28142?
CVE-2026-28142 affects all versions of the Web Directory Free plugin up to and including version 1.7.13.
5
Is authentication required to exploit CVE-2026-28142?
No, CVE-2026-28142 can be exploited without authentication.