Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wpwax

First CVE: Dec 21, 2021Active for: 5 yearsTotal CVEs: 31
32.8
VTI Score
Medium

Wpwax develops a modestly represented suite of WordPress plugins and extensions spanning directory listing, content presentation, e-commerce, and team management functionality. The vendor's vulnerability exposure is rooted in web-application input handling and access control, with recurrent weakness classes including cross-site request forgery, cross-site scripting, missing authorization, and untrusted deserialization—patterns typical of plugins that process user input or handle sensitive data within WordPress environments. A moderate tendency toward public exploit availability characterizes this vendor's disclosures, reflecting the appeal of WordPress plugin vulnerabilities to both security researchers and threat actors. Defenders relying on these plugins should maintain close attention to update cycles and restrict administrative access; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wpwax over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 21, 2021
4 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-59518CRITICAL
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.
Jul 13, 20269.841NONO
CVE-2024-2006HIGH
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and
Mar 13, 20248.830NONO
CVE-2025-1570CRITICAL
The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions u
Feb 28, 20259.828NONO
CVE-2024-13409HIGH
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and
Jan 24, 20258.825NONO
CVE-2024-1950HIGH
The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserializati
Mar 13, 20248.825NONO
CVE-2023-1888HIGH
The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within lo
Jun 9, 20238.825NONO
CVE-2025-24782HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate post-grid-carou
Jan 27, 20258.824NONO
CVE-2023-41798HIGH
Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Di
Nov 7, 20238.824NONO
CVE-2021-24981HIGH
The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins
Dec 21, 20217.524NONO
CVE-2025-68069HIGH
Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/
Feb 20, 20267.123NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
58%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (96.8%)
High1 (3.2%)
Unknown0 (0.0%)
User Interaction
None22 (71.0%)
Unknown0 (0.0%)
Required9 (29.0%)
Privileges Required
Low16 (51.6%)
High3 (9.7%)
None12 (38.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
6.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwax.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wpwax — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wpwax's Products

View all 3 CNAs →

Top CWEs