A vulnerability was found in mihail-chepovskiy Web Directory Free Plugin up to 1.7.13 on WordPress. It has been declared as critical. The impacted element is an unknown function. Executing a manipulation of the argument levels can lead to sql injection.

This vulnerability is registered as CVE-2026-14785. It is possible to launch the attack remotely. No exploit is available.