{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/mihail-chepovskiy/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-14785"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Web Directory Free (\u003c= 1.7.13)"],"_cs_severities":["high"],"_cs_tags":["sql-injection","wordpress","plugin","web","cve"],"_cs_type":"advisory","_cs_vendors":["mihail-chepovskiy"],"content_html":"\u003cp\u003eA critical SQL Injection vulnerability, tracked as CVE-2026-14785, has been identified in the Web Directory Free plugin for WordPress, affecting all versions up to and including 1.7.13. This flaw stems from insufficient escaping of user-supplied input to the 'levels' parameter and inadequate preparation of existing SQL queries. The vulnerability allows unauthenticated attackers to inject malicious SQL code, appending it to legitimate database queries. Successful exploitation can lead to the extraction of sensitive information from the underlying database, such as user credentials, personal data, or configuration details. This presents a significant risk to the confidentiality of data hosted on affected WordPress sites.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker crafts a malicious HTTP GET or POST request targeting a vulnerable endpoint of the WordPress Web Directory Free plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker includes a specially crafted SQL injection payload within the 'levels' parameter of the HTTP request.\u003c/li\u003e\n\u003cli\u003eThe vulnerable plugin, due to inadequate input sanitization, processes the request and appends the attacker's SQL payload to an existing database query.\u003c/li\u003e\n\u003cli\u003eThe manipulated query is sent to the WordPress database, where the malicious SQL commands are executed.\u003c/li\u003e\n\u003cli\u003eThe database processes the injected query, which could be designed to select, union, or otherwise retrieve sensitive data from tables.\u003c/li\u003e\n\u003cli\u003eThe results of the malicious query, including the extracted sensitive information, are returned in the HTTP response to the attacker.\u003c/li\u003e\n\u003cli\u003eThe attacker parses the HTTP response to collect the sensitive data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-14785 can lead to unauthorized access and exfiltration of sensitive information stored in the WordPress database. This could include user credentials (usernames and hashed passwords), personal identifiable information (PII) of registered users, configuration settings, and other proprietary data. The compromise of such data can result in significant financial, reputational, and regulatory damage for organizations utilizing the vulnerable plugin. While no specific victim numbers or targeted sectors are mentioned, any WordPress site using the Web Directory Free plugin up to version 1.7.13 is susceptible.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Web Directory Free plugin for WordPress to a version patched against CVE-2026-14785.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-14785 Exploitation - WordPress Web Directory Free SQL Injection\u0026quot; to your SIEM to detect exploitation attempts.\u003c/li\u003e\n\u003cli\u003eConfigure web server logging (e.g., Apache, Nginx, IIS) to capture \u003ccode\u003ecs-uri-stem\u003c/code\u003e and \u003ccode\u003ecs-uri-query\u003c/code\u003e for all HTTP requests to aid in detecting and investigating web-based attacks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T10:21:06Z","date_published":"2026-07-28T10:21:06Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-web-directory-free-sqli/","summary":"The Web Directory Free plugin for WordPress, in all versions up to and including 1.7.13, is vulnerable to generic SQL Injection through the 'levels' parameter. This flaw, caused by insufficient input escaping and lack of query preparation, enables unauthenticated attackers to append arbitrary SQL queries to existing ones, allowing them to extract sensitive information directly from the database.","title":"Generic SQL Injection Vulnerability in WordPress Web Directory Free Plugin (CVE-2026-14785)","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-web-directory-free-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Mihail-Chepovskiy","version":"https://jsonfeed.org/version/1.1"}