Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.17% | — | Wpwax DirectoristAI | 23/9/2026 | 23/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches the authenticated caller before reading and modifying that user's saved favorites, allowing any authenticated user with subscriber-level access to view… | |
| Aplazada | Media (6.5) | 0.21% | — | Wpwax DirectoristAI | 23/9/2026 | 23/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and above to delete arbitrary listings, including ones belonging to other users. This… | |
| Aplazada | Media (5) | 0.20% | — | Wpwax DirectoristAI | 23/9/2026 | 23/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the server issue requests to internal addresses. | |
| Aplazada | Media (4.3) | 0.18% | — | Wpwax DirectoristAI | 23/9/2026 | 23/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to create paid order and payment records with arbitrary amounts and attribute them to… | |
| Aplazada | Media (5.3) | 0.25% | — | Wpwax DirectoristAI | 23/9/2026 | 23/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' private contact details. | |
| Aplazada | Media (4.3) | 0.20% | — | Wpwax DirectoristAI | 23/9/2026 | 23/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read every customer's order and payment records. Versions 8.8.1 to 8.9 are not affected.… | |
| Aplazada | Baja (3.1) | 0.21% | — | Wpwax DirectoristAI | 4/9/2026 | 8/9/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above to overwrite image metadata on posts… | |
| Aplazada | Media (5.4) | 0.29% | — | Wpwax DirectoristAI | 26/8/2026 | 26/8/2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the source of a file move, allowing users with a subscriber-level account to relocate arbitrary server-readable image files into a publicly… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpwax DirectoristAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpwax Directorist BookingAI | 17/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Directorist Social LoginAI | 27/4/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Directorist Directorist Social Login allows Privilege Escalation.This issue affects Directorist Social Login: from n/a before 2.1.4. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Directorist BookingAI | 27/4/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Directorist Booking allows SQL Injection.This issue affects Directorist Booking: from n/a before 3.0.2. | |
| Aplazada | Media (5.3) | 0.29% | — | Wpwax DirectoristAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.5.10. | |
| Aplazada | Alta (7.1) | 0.32% | — | Wpwax DirectoristAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through <= 8.6.6. | |
| Aplazada | Media (4.7) | 0.24% | — | Wpwax DirectoristAI | 16/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wpWax Directorist directorist allows Phishing.This issue affects Directorist: from n/a through <= 8.6.6. | |
| Aplazada | Media (6.5) | 0.20% | — | Wpwax DirectoristAI | 19/11/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'directorist_prepare_listings_export_file' and 'directorist_type_slug_change' AJAX actions in all versions up to, and including, 8.5.2.… | |
| Aplazada | Alta (8.1) | 0.91% | — | Wpwax DirectoristAI | 25/10/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to arbitrary file move due to insufficient file path validation in the add_listing_action AJAX action in all versions up to, and including, 8.4.8. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.5) | 0.27% | — | Wpwax Directorist Addonskit FOR ElementorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpWax Directorist AddonsKit for Elementor addonskit-for-elementor allows Stored XSS.This issue affects Directorist AddonsKit for Elementor: from n/a through <= 1.1.6. | |
| Aplazada | Media (5.3) | 0.41% | — | Wpwax DirectoristAI | 25/3/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'parse_query' function in all versions up to, and including, 8.2. This makes it possible for unauthenticated… | |
| Analizada | Crítica (9.8) | 0.44% | — | Wpwax Directorist | 28/2/2025 | 17/6/2026 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 8.1. This is due to the directorist_generate_password_reset_pin_code() and reset_user_password() functions not having… | |
| Analizada | Media (5.3) | 0.41% | — | Wpwax Directorist | 1/2/2025 | 17/6/2026 | The Directorist: AI-Powered WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 8.0.12 via the /wp-json/directorist/v1/users/ endpoint. This makes it possible for unauthenticated attackers to extract sensitive… | |
| Aplazada | Media (4.3) | 0.39% | — | Wpwax DirectoristAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in wpWax - WP Business Directory Plugin and Classified Listings Directory Directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/a through 7.5.4. | |
| Aplazada | Media (5.3) | 0.36% | — | Wpwax DirectoristAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6. | |
| Modificada | Media (5.3) | 0.52% | — | Wpwax Directorist | 29/2/2024 | 17/6/2026 | The Directorist – WordPress Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 7.8.4. This makes it possible for unauthenticated attackers… | |
| Modificada | Baja (2.7) | 1.3% | — | Wpwax Directorist | 16/1/2024 | 17/6/2026 | The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file parameter when importing CSV files. |