Skip to main content

Vendor archive

wpwax CVEs

Beta · best-effort

23 CVEs tagged to vendor wpwax0 Critical, 6 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2025-1570

Published Feb 28, 2025

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12041

Published Feb 1, 2025

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24782

Published Jan 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate post-grid-caro…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13409

Published Jan 24, 2025

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29925

Published Mar 27, 2024

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate allows Stored XSS.This issue affe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50886

Published Mar 15, 2024

Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2006

Published Mar 13, 2024

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1322

Published Feb 29, 2024

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2252

Published Jan 16, 2024

The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files.

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-47824

Published Nov 22, 2023

Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin <= 1.3.8 versions.

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-41798

Published Nov 7, 2023

Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects D…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-1889

Published Jun 9, 2023

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to improper validation and authoriza…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-1888

Published Jun 9, 2023

The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within l…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2022-3961

Published Dec 19, 2022

The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3930

Published Dec 12, 2022

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary users instead of his own.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2376

Published Sep 5, 2022

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any authenticated users

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2377

Published Aug 22, 2022

The Directorist WordPress plugin before 7.3.0 does not have authorisation and CSRF checks in an AJAX action, allowing any authenticated users to send arbitrary emails on behalf of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2046

Published Aug 8, 2022

The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34853

Published Jul 22, 2022

Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34650

Published Jul 22, 2022

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1266

Published Jun 20, 2022

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24981

Published Dec 21, 2021

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1