Vulnerabilidades em wpWax
37 resultadosCVE-2024-12041MEDIUMDirectorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information ExposureEPSS 0.4%CVE-2024-33929MEDIUMWordPress Directorist plugin <= 7.8.6 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-8046MEDIUMLogo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File UploadEPSS 0.3%CVE-2025-24681MEDIUMWordPress Product Carousel Slider & Grid Ultimate for WooCommerce Plugin <= 1.10.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2024-29925MEDIUMWordPress Post Grid, Slider & Carousel Ultimate plugin <= 1.6.6 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-48242MEDIUMWordPress Legal Pages plugin <= 1.4.5 - Broken Access Control VulnerabilityEPSS 0.3%CVE-2025-68069HIGHWordPress Directorist plugin <= 8.6.6 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2025-39525MEDIUMWordPress Logo Carousel Slider plugin <= 2.1.3 - Cross Site Scripting (XSS) VulnerabilityEPSS 0.3%CVE-2023-47824MEDIUMWordPress Legal Pages Plugin <= 1.3.8 is vulnerable to Cross Site Request Forgery (CSRF)EPSS 0.3%CVE-2025-31857MEDIUMWordPress Directorist AddonsKit for Elementor plugin <= 1.1.6 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-66077MEDIUMWordPress Legal Pages plugin <= 1.4.6 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-39509MEDIUMWordPress Directorist plugin <= 8.5.10 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2024-32451MEDIUMWordPress Legal Pages plugin <= 1.4.2 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2023-50886MEDIUMWordPress Legal Pages plugin <= 1.3.7 - CSRF + Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-49073HIGHWordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerabilityEPSS 0.2%CVE-2025-64250MEDIUMWordPress Directorist plugin <= 8.6.6 - Open Redirection vulnerabilityEPSS 0.2%CVE-2025-12174MEDIUMDirectorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug UpdateEPSS 0.2%