Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Directorist CRITICAL 9.8
CVE-2025-1570

The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via acc…

Fix: 8.2+
Fix from $2,300 2025-02-28
Directorist MEDIUM 5.3
CVE-2024-12041

The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposu…

Fix: 8.1+
Fix from $1,600 2025-02-01
Post Grid\, Slider \& Carousel Ultimate HIGH 8.8
CVE-2025-24782

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Ca…

Fix: 1.7+
Fix from $1,950 2025-01-27
Post Grid\, Slider \& Carousel Ultimate HIGH 8.8
CVE-2024-13409

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclu…

Fix: 1.7+
Fix from $1,950 2025-01-24
Post Grid\, Slider \& Carousel Ultimate MEDIUM 5.4
CVE-2024-29925

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate all…

Fix: 1.6.7+
Fix from $1,600 2024-03-27
Legal Pages HIGH 8.0
CVE-2023-50886

Cross-Site Request Forgery (CSRF), Incorrect Authorization vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1.3.7.

Fix: 1.3.8+
Fix from $1,950 2024-03-15
Post Grid\, Slider \& Carousel Ultimate HIGH 8.8
CVE-2024-2006

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injec…

Fix: 1.6.8+
Fix from $1,950 2024-03-13
Product Carousel Slider \& Grid Ultimate For Woocommerce HIGH 8.8
CVE-2024-1950

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc…

Fix: 1.9.8+
Fix from $1,950 2024-03-13
Directorist MEDIUM 5.3
CVE-2024-1322

The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of…

Fix: 7.8.5+
Fix from $1,600 2024-02-29
Legal Pages HIGH 8.8
CVE-2023-47824

Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator pl…

Fix: 1.3.9+
Fix from $1,950 2023-11-22
Directorist HIGH 8.8
CVE-2023-41798

Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ad…

Fix: after 7.7.1
Fix from $1,950 2023-11-07
Directorist HIGH 8.8
CVE-2023-1888

The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack…

Fix: after 7.5.4
Fix from $1,950 2023-06-09
Directorist MEDIUM 6.5
CVE-2023-1889

The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, 7.5.4. This is due to imp…

Fix: after 7.5.4
Fix from $1,600 2023-06-09
Directorist MEDIUM 6.5
CVE-2022-3961

The Directorist WordPress plugin before 7.4.4 does not prevent users with low privileges (like subscribers) from accessing sensitive system informati…

Fix: 7.4.4+
Fix from $1,600 2022-12-19
Directorist MEDIUM 6.5
CVE-2022-3930

The Directorist WordPress plugin before 7.4.2.2 suffers from an IDOR vulnerability which an attacker can exploit to change the password of arbitrary…

Fix: 7.4.2.2+
Fix from $1,600 2022-12-12
Directorist MEDIUM 5.3
CVE-2022-2376

The Directorist WordPress plugin before 7.3.1 discloses the email address of all users in an AJAX action available to both unauthenticated and any au…

Fix: 7.3.1+
Fix from $1,600 2022-09-05
Team MEDIUM 5.4
CVE-2022-34853

Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordP…

Fix: after 1.2.6
Fix from $1,600 2022-07-22
Team MEDIUM 5.4
CVE-2022-34650

Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.

Fix: after 1.2.6
Fix from $1,600 2022-07-22
Directorist HIGH 7.5
CVE-2021-24981

The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell upl…

Fix: 7.0.6.2+
Fix from $1,950 2021-12-21