Vulnerabilities (CVE)

Filtered by vendor Wpwax Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-47824 1 Wpwax 1 Legal Pages 2023-11-29 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator plugin <= 1.3.8 versions.
CVE-2023-41798 1 Wpwax 1 Directorist 2023-11-14 N/A 8.8 HIGH
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Directorist – WordPress Business Directory Plugin with Classified Ads Listings: from n/a through 7.7.1.
CVE-2022-34650 1 Wpwax 1 Team 2022-07-26 N/A 5.4 MEDIUM
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.
CVE-2022-34853 1 Wpwax 1 Team 2022-07-25 N/A 5.4 MEDIUM
Multiple Authenticated (contributor or higher user role) Persistent Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.
CVE-2022-1266 1 Wpwax 1 Post Grid\, Slider \& Carousel Ultimate 2022-06-30 3.5 LOW 4.8 MEDIUM
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2021-24981 1 Wpwax 1 Directorist 2021-12-27 5.1 MEDIUM 7.5 HIGH
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.