← Back

Wpwax

wpwax

23 CVEs • 5 products

Products (5)

Click to collapse
Toggle

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpwax
1Team
Jun 17, 2026
Jul 22, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in wpWax Team plugin <= 1.2.6 at WordPress.
1Wpwax
1Post Grid, Slider & Carousel Ultimate
Jun 17, 2026
Jun 20, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilter...Show more
The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.5.0 does not sanitise and escape the Header Title, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less
1Wpwax
1Directorist
Jun 17, 2026
Dec 21, 2021
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.