Wpwax develops a modestly represented suite of WordPress plugins and extensions spanning directory listing, content presentation, e-commerce, and team management functionality. The vendor's vulnerability exposure is rooted in web-application input handling and access control, with recurrent weakness classes including cross-site request forgery, cross-site scripting, missing authorization, and untrusted deserialization—patterns typical of plugins that process user input or handle sensitive data within WordPress environments. A moderate tendency toward public exploit availability characterizes this vendor's disclosures, reflecting the appeal of WordPress plugin vulnerabilities to both security researchers and threat actors. Defenders relying on these plugins should maintain close attention to update cycles and restrict administrative access; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpwax over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59518CRITICAL Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2. | Jul 13, 2026 | 9.8 | 41 | NO | NO |
CVE-2024-2006HIGH The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and | Mar 13, 2024 | 8.8 | 30 | NO | NO |
CVE-2025-1570CRITICAL The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions u | Feb 28, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-13409HIGH The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and | Jan 24, 2025 | 8.8 | 25 | NO | NO |
CVE-2024-1950HIGH The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.7 via deserializati | Mar 13, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-1888HIGH The Directorist plugin for WordPress is vulnerable to an arbitrary user password reset in versions up to, and including, 7.5.4. This is due to a lack of validation checks within lo | Jun 9, 2023 | 8.8 | 25 | NO | NO |
CVE-2025-24782HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Post Grid, Slider & Carousel Ultimate post-grid-carou | Jan 27, 2025 | 8.8 | 24 | NO | NO |
CVE-2023-41798HIGH Improper Neutralization of Formula Elements in a CSV File vulnerability in wpWax Directorist – WordPress Business Directory Plugin with Classified Ads Listing.This issue affects Di | Nov 7, 2023 | 8.8 | 24 | NO | NO |
CVE-2021-24981HIGH The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins | Dec 21, 2021 | 7.5 | 24 | NO | NO |
CVE-2025-68069HIGH Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Directorist: from n/ | Feb 20, 2026 | 7.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpwax.
Media articles that mention a CVE ID that affects a product developed by Wpwax — matched by CVE ID, not by vendor name.