Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Directorist
wpWax
Developer
8.5.4
Latest version
20,000
Installations
6 hours ago
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Vulnerability history
0 present
16 fixed
8 Mitigation rules
Authenticated (Subscriber+) Arbitrary File Move vulnerability
<= 8.4.8
Oct 25, 2025
Missing Authorization to Unauthenticated Arbitrary Post Publishing vulnerability
<= 8.2
Mar 24, 2025
Privilege Escalation and Account Takeover via Weak OTP vulnerability
<= 8.1
Feb 27, 2025
Unauthenticated User Information Exposure vulnerability
<= 8.0.12
Jan 31, 2025
Broken Access Control vulnerability
<= 7.8.6
Apr 29, 2024
Missing Authorization to Unauthenticated Settings Change vulnerability
<= 7.8.4
Feb 13, 2024
CSV Injection
<= 7.7.1
Sep 5, 2023
Broken Access Control
<= 7.7.1
Sep 4, 2023
Arbitrary Content Deletion vulnerability
<= 7.5.4
Jun 13, 2023
Authenticated Privilege Escalation Vulnerability
<= 7.5.4
Jun 7, 2023
Authenticated Arbitrary Post Deletion Vulnerability
<= 7.5.4
Jun 7, 2023
Auth. Insecure Direct Object References (IDOR) vulnerability
<= 7.4.2.1
Nov 21, 2022
Unauthenticated Email Address Disclosure vulnerability
<= 7.3.0
Aug 10, 2022
Authenticated Arbitrary E-mail Sending vulnerability
<= 7.2.3
Jul 26, 2022
Authenticated Arbitrary File Upload vulnerability
<= 7.2.2
Jul 18, 2022
Cross-Site Request Forgery (CSRF) vulnerability leading to Remote File Upload
<= 7.0.6.1
Nov 18, 2021