| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-2278 | WP Directory Kit <= 1.1.9 - Unauthenticated Local File Inclusion via wdk_public_action | wpdirectorykit | WP Directory Kit | Critical | 9.8 | 2023-06-13 01:48:07 | Deep Dive |
| CVE-2023-2351 | WP Directory Kit <= 1.2.3 - Missing Authorization to Plugin Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_admin_action | wpdirectorykit | WP Directory Kit | Medium | 6.5 | 2023-06-13 01:48:06 | Deep Dive |
| CVE-2023-1889 | Directorist <= 7.5.4 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion in listing_task | wpwax | Directorist: AI-Powered Business Directory, Listings & Classified Ads | Medium | 6.5 | 2023-06-09 05:33:29 | Deep Dive |
| CVE-2023-2280 | WP Directory Kit <= 1.2.2 - Missing Authorization to Plugin Installation, Settings Change/Delete, Demo Import, Directory Kit Deletion via wdk_public_action | wpdirectorykit | WP Directory Kit | Medium | 6.5 | 2023-06-09 05:33:26 | Deep Dive |
| CVE-2023-2599 | Active Directory Integration / LDAP Integration <= 4.1.4 - Cross-Site Request Forgery to SQL Injection | cyberlord92 | Active Directory Integration / LDAP Integration | Low | 3.1 | 2023-06-09 05:33:21 | Deep Dive |
| CVE-2023-2484 | Active Directory Integration / LDAP Integration <= 4.1.4 - Authenticated (Administrator+) SQL Injection | cyberlord92 | Active Directory Integration / LDAP Integration | High | 7.2 | 2023-06-09 05:33:15 | Deep Dive |
| CVE-2023-1888 | Directorist <= 7.5.4 - Authenticated (Subscriber+) Arbitrary User Password Reset to Privilege Escalation | wpwax | Directorist: AI-Powered Business Directory, Listings & Classified Ads | High | 8.8 | 2023-06-09 05:33:09 | Deep Dive |
| CVE-2021-4381 | uListing <= 1.6.6 - Unauthenticated Options Changes via wp_route | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:55 | Deep Dive |
| CVE-2021-4370 | uListing <= 1.6.6 - Missing Authorization | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:43 | Deep Dive |
| CVE-2020-36723 | ListingPro - WordPress Directory & Listing Theme < 2.6.1 - Sensitive Information Disclosure | - | ListingPro - WordPress Directory & Listing Theme | Medium | 5.3 | 2023-06-07 01:51:41 | Deep Dive |
| CVE-2020-36719 | ListingPro - WordPress Directory & Listing Theme < 2.6.1 - Arbitrary Plugin Installation, Activation and Deactivation | - | ListingPro - WordPress Directory & Listing Theme | Critical | 9.8 | 2023-06-07 01:51:35 | Deep Dive |
| CVE-2021-4357 | uListing <= 1.6.6 - Unauthenticated Arbitrary Post/Page Deletion | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.1 | 2023-06-07 01:51:26 | Deep Dive |
| CVE-2021-4345 | uListing <= 1.6.6 - Unauthenticated Arbitrary Roles and Capabilities Creation/Deletion | stylemix | Directory Listings WordPress plugin – uListing | Medium | 6.5 | 2023-06-07 01:51:18 | Deep Dive |
| CVE-2021-4346 | uListing <= 1.6.6 - Unauthenticated Arbitrary Account Changes | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:17 | Deep Dive |
| CVE-2021-4343 | uListing <= 1.6.6 - Unauthenticated Arbitrary Account Creation | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:15 | Deep Dive |
| CVE-2021-4341 | uListing <= 1.6.6 - Unauthenticated Wordpress Options Changes via AJAX | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:13 | Deep Dive |
| CVE-2021-4339 | uListing <= 1.6.6 - Unauthenticated Information Disclosure | stylemix | Directory Listings WordPress plugin – uListing | High | 7.5 | 2023-06-07 01:51:12 | Deep Dive |
| CVE-2021-4340 | uListing <= 1.6.6 - Unauthenticated SQL Injection | stylemix | Directory Listings WordPress plugin – uListing | Critical | 9.8 | 2023-06-07 01:51:12 | Deep Dive |
| CVE-2023-2835 | WP Directory Kit <= 1.2.3 - Reflected Cross-Site Scripting via 'search' | wpdirectorykit | WP Directory Kit | Medium | 6.1 | 2023-06-02 06:06:48 | Deep Dive |
| CVE-2023-2201 | Web Directory Free <= 1.6.8 - Authenticated (Contributor+) SQL Injection via post_id | mihail-chepovskiy | Web Directory Free | High | 8.8 | 2023-06-02 03:36:06 | Deep Dive |