The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
https://github.com/Nxploited/CVE-2024-3673
https://wpscan.com/vulnerability/0e8930cb-e176-4406-a43f-a6032471debf/