CVEs we hold for Wpwax
Records whose assigning authority named Wpwax as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-59518WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerabilitywpWax Directorist
CVE-2026-49073WordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerabilitywpWax Directorist Booking
CVE-2026-39509WordPress Directorist plugin <= 8.5.10 - Broken Access Control vulnerabilitywpWax Directorist
CVE-2026-32474WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerabilitywpWax Templatiq
CVE-2026-3141FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameterwpwax FormGent – Next-Gen AI Form Builder for WordPress…
CVE-2026-22460WordPress FormGent plugin <= 1.7.0 - Arbitrary File Deletion vulnerabilitywpWax FormGent
CVE-2025-68069WordPress Directorist plugin <= 8.6.6 - Broken Access Control vulnerabilitywpWax Directorist
CVE-2025-66077WordPress Legal Pages plugin <= 1.4.6 - Broken Access Control vulnerabilitywpWax Legal Pages
CVE-2025-64250WordPress Directorist plugin <= 8.6.6 - Open Redirection vulnerabilitywpWax Directorist
CVE-2025-48242WordPress Legal Pages plugin <= 1.4.5 - Broken Access Control VulnerabilitywpWax Legal Pages
CVE-2025-39525WordPress Logo Carousel Slider plugin <= 2.1.3 - Cross Site Scripting (XSS) VulnerabilitywpWax Logo Carousel Slider
CVE-2025-32499WordPress Logo Showcase Ultimate plugin <= 1.4.4 - Local File Inclusion vulnerabilitywpWax Logo Showcase Ultimate
CVE-2025-31857WordPress Directorist AddonsKit for Elementor plugin <= 1.1.6 - Cross Site Scripting (XSS) vulnerabilitywpWax Directorist AddonsKit for Elementor
CVE-2025-24782WordPress Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 -…wpWax Post Grid, Slider & Carousel Ultimate
CVE-2025-24681WordPress Product Carousel Slider & Grid Ultimate for WooCommerce Plugin <= 1.10.0 - Cross Site Scripting (XSS)…wpWax Product Carousel Slider & Grid Ultimate for…
CVE-2025-2224Directorist <= 8.2 - Missing Authorization to Unauthenticated Arbitrary Post Publishingwpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2025-1570Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.1 - Privilege Escalation and…wpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2025-15028FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated…wpwax FormGent – Next-Gen AI Form Builder for WordPress…
CVE-2025-12174Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to…wpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2025-10488Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+)…wpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2024-8046Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid <= 1.4.1 - Authenticated (Author+) Stored Cross-Site…wpwax Logo Showcase Ultimate – Logo Carousel, Logo Slider &…
CVE-2024-44048WordPress Product Carousel Slider & Grid Ultimate for WooCommerce plugin <= 1.9.10 - Authenticated Local File Inclusion…wpWax Product Carousel Slider & Grid Ultimate for…
CVE-2024-33929WordPress Directorist plugin <= 7.8.6 - Broken Access Control vulnerabilitywpWax Directorist
CVE-2024-32451WordPress Legal Pages plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) vulnerabilitywpWax Legal Pages
CVE-2024-29925WordPress Post Grid, Slider & Carousel Ultimate plugin <= 1.6.6 - Cross Site Scripting (XSS) vulnerabilitywpWax Post Grid, Slider & Carousel Ultimate
CVE-2024-2006Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated…wpwax Post Grid, Slider & Carousel Ultimate – with…
CVE-2024-1951Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid <= 1.3.8 - Authenticated(Contributor+) PHP Object…wpwax Logo Showcase Ultimate – Logo Carousel, Logo Slider &…
CVE-2024-1950Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.9.7 - Authenticated(Contributor+) PHP Object Injectionwpwax Product Carousel Slider & Grid Ultimate for…
CVE-2024-13409Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated…wpwax Post Grid, Slider & Carousel Ultimate – with…
CVE-2024-13408Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated…wpwax Post Grid, Slider & Carousel Ultimate – with…
CVE-2024-1322Directorist <= 7.8.4 - Missing Authorization to Unauthenticated Settings Changewpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2024-12041Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated…wpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2024-12040Product Carousel Slider & Grid Ultimate for WooCommerce <= 1.9.10 - Authenticated (Contributor+) Local File Inclusion…wpwax Product Carousel Slider & Grid Ultimate for…
CVE-2023-50886WordPress Legal Pages plugin <= 1.3.7 - CSRF + Broken Access Control vulnerabilitywpWax Legal Pages
CVE-2023-47824WordPress Legal Pages Plugin <= 1.3.8 is vulnerable to Cross Site Request Forgery (CSRF)wpWax Legal Pages – Privacy Policy, Terms & Conditions…
CVE-2023-41798WordPress Directorist Plugin <= 7.7.1 is vulnerable to CSV InjectionwpWax Directorist – WordPress Business Directory Plugin…
CVE-2023-35052WordPress Directorist plugin <= 7.5.4 - Arbitrary Content Deletion vulnerabilitywpWax - WP Business Directory Plugin and Classified…
CVE-2023-1889Directorist <= 7.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion in…wpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2023-1888Directorist <= 7.5.4 - Authenticated (Subscriber+) Arbitrary User Password Reset to Privilege Escalationwpwax Directorist: AI-Powered Business Directory, Listings…
CVE-2022-34853WordPress Team plugin <= 1.2.6 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilitieswpWax Team (WordPress plugin)
CVE-2022-34650WordPress Team plugin <= 1.2.6 - Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilitieswpWax Team (WordPress plugin)
42 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.