CVE Tools

Wpwax

5 CVEs tracked since 2024. Since Mar 2024, none of them reached CISA KEV.

Wpwax CVEs per month

Mar 2024 to Mar 2024. Point at a month, or focus the strip and use the arrow keys.
Wpwax CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-0350

Products

The products that kept showing up in Wpwax's monthly top three, with their CVEs summed over those months.

  1. Post Grid\, Slider \& Carousel Ultimate21 month
  2. Product Carousel Slider \& Grid Ultimate For Woocommerce11 month
  3. Product Carousel Slider & Grid Ultimate For Woocommerce11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Wpwax.

  1. CVE-2026-32474WordPress Templatiq plugin <= 0.2.5 - Arbitrary File Upload vulnerability9.9
  2. CVE-2025-15028FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting7.2
  3. CVE-2026-3141FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter9.1
  4. CVE-2026-59518WordPress Directorist plugin <= 8.8.2 - PHP Object Injection vulnerability9.8
  5. CVE-2026-49073WordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerability8.5
  6. CVE-2026-39509WordPress Directorist plugin <= 8.5.10 - Broken Access Control vulnerability5.3
  7. CVE-2026-22460WordPress FormGent plugin <= 1.7.0 - Arbitrary File Deletion vulnerability8.6
  8. CVE-2025-68069WordPress Directorist plugin <= 8.6.6 - Broken Access Control vulnerability7.1
  9. CVE-2025-64250WordPress Directorist plugin <= 8.6.6 - Open Redirection vulnerability4.7
  10. CVE-2025-66077WordPress Legal Pages plugin <= 1.4.6 - Broken Access Control vulnerability5.3
  11. CVE-2025-12174Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.5.2 - Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update6.5
  12. CVE-2025-10488Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File Move8.1
  13. CVE-2025-48242WordPress Legal Pages plugin <= 1.4.5 - Broken Access Control Vulnerability6.5
  14. CVE-2025-32658WordPress HelpGent plugin <= 2.2.5 - PHP Object Injection vulnerability9.8
  15. CVE-2025-39525WordPress Logo Carousel Slider plugin <= 2.1.3 - Cross Site Scripting (XSS) Vulnerability6.5

The record

Peak rank
#177 in Mar 2024
Busiest month shown
Mar 2024, 5 CVEs
Months with a KEV entry
0 since Mar 2024
Monthly snapshots
1 since 2024
Wpwax's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store