Name Directory - Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' vulnerability
high
Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' vulnerability
- CVSS:
- 7.1
- Affected:
- up to 1.32.1
- Fixed in:
- 1.33.0
- Disclosed:
- Mar 12, 2026
Name Directory <= 1.32.1 - Unauthenticated Stored Cross-Site Scripting via 'name_directory_name'
high
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' parameter in all versions up to, and including, 1.32.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 7.2
- Affected:
- up to 1.32.1
- Fixed in:
- 1.33.0
- Disclosed:
- Mar 10, 2026
CVE-2026-3178 on NVD →
Name Directory <= 1.32.0 - Unauthenticated Stored Cross-Site Scripting via Double HTML-Entity Encoding in Submission Form
high
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via double HTML-entity encoding in all versions up to, and including, 1.32.0. This is due to the plugin's sanitization function calling `html_entity_decode()` before `wp_kses()`, and then calling `html_entity_decode()` again on output....
- CVSS:
- 7.2
- Affected:
- up to 1.32.0
- Fixed in:
- 1.32.1
- Disclosed:
- Feb 9, 2026
CVE-2026-1866 on NVD →
Name Directory [name-directory] < 1.31.0
unknown
[en] The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and 'name_directory_description' parameters in all versions up to, and including, 1.30.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...
- Affected:
- up to 1.31.0
- Fixed in:
- 1.31.0
- Disclosed:
- Jan 14, 2026
CVE-2025-15283 on NVD →
Name Directory <= 1.30.3 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters
high
The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and 'name_directory_description' parameters in all versions up to, and including, 1.30.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 7.2
- Affected:
- up to 1.30.3
- Fixed in:
- 1.31.0
- Disclosed:
- Jan 13, 2026
CVE-2025-15283 on NVD →
Name Directory [name-directory] < 1.30.1
unknown
[en] Missing Authorization vulnerability in Jeroen Peters Name Directory.This issue affects Name Directory: from n/a through 1.30.0.
- Affected:
- up to 1.30.1
- Fixed in:
- 1.30.1
- Disclosed:
- May 19, 2025
CVE-2025-39454 on NVD →
Name Directory <= 1.30.0 - Missing Authorization
medium
The Name Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.30.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.30.0
- Fixed in:
- 1.30.1
- Disclosed:
- Apr 17, 2025
CVE-2025-39454 on NVD →
Name Directory [name-directory] < 1.29.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Peters Name Directory allows Reflected XSS.This issue affects Name Directory: from n/a through 1.29.0.
- Affected:
- up to 1.29.1
- Fixed in:
- 1.29.1
- Disclosed:
- Sep 17, 2024
CVE-2024-43938 on NVD →
Name Directory <= 1.29.0 - Reflected Cross-Site Scripting
medium
The Name Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 1.29.0
- Fixed in:
- 1.29.1
- Disclosed:
- Aug 26, 2024
CVE-2024-43938 on NVD →
Name Directory [name-directory] < 1.27.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions.
- Affected:
- up to 1.27.2
- Fixed in:
- 1.27.2
- Disclosed:
- May 22, 2023
CVE-2023-22692 on NVD →
Name Directory <= 1.27.1 - Cross Site Request Forgery
medium
The Name Directory plugin for WordPress is vulnerable to Cross Site Request Forgery in versions up to, and including, 1.27.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can trick a site administra...
- CVSS:
- 4.3
- Affected:
- up to 1.27.1
- Fixed in:
- 1.27.2
- Disclosed:
- Jan 23, 2023
CVE-2023-22692 on NVD →
Name Directory [name-directory] < 1.25.4
unknown
[en] The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.
- Affected:
- up to 1.25.4
- Fixed in:
- 1.25.4
- Disclosed:
- Jul 25, 2022
CVE-2022-2071 on NVD →
Name Directory [name-directory] < 1.25.4
unknown
[en] The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well
- Affected:
- up to 1.25.4
- Fixed in:
- 1.25.4
- Disclosed:
- Jul 25, 2022
CVE-2022-2072 on NVD →
Name Directory [name-directory] < 1.25.5
unknown
Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress Name Directory plugin (versions <= 1.25.4).
Update the WordPress Name Directory plugin to the latest available version (at least 1.25.5).
- Affected:
- up to 1.25.5
- Fixed in:
- 1.25.5
- Disclosed:
- Jul 18, 2022
Name Directory <= 1.25.4 - Unauthorized Settings Update
medium
The Name Directory plugin for WordPress is vulnerable to unauthorized settings update due to insufficient permissions checking on the name_directory_options() function in versions up to, and including, 1.25.4. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to perform....
- CVSS:
- 6.3
- Affected:
- up to 1.25.4
- Fixed in:
- 1.25.5
- Disclosed:
- Jul 15, 2022
Name Directory [name-directory] < 1.25.5
unknown
The Name Directory plugin for WordPress is vulnerable to unauthorized settings update due to insufficient permissions checking on the name_directory_options() function in versions up to, and including, 1.25.4. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to perform....
- Affected:
- up to 1.25.5
- Fixed in:
- 1.25.5
- Disclosed:
- Jul 15, 2022
Name Directory <= 1.25.3 - Cross-Site Request Forgery
high
The Name Directory plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.25.3. This is due to missing or incorrect nonce validation when editing, deleting or naming directories. This makes it possible for unauthenticated attackers to trigger the above actions via forged re...
- CVSS:
- 8.8
- Affected:
- up to 1.25.3
- Fixed in:
- 1.25.4
- Disclosed:
- Jun 28, 2022
CVE-2022-2071 on NVD →
Name Directory [name-directory] < 1.25.4
unknown
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were discovered in the WordPress Name Directory plugin (versions <= 1.25.3).
Update the WordPress Name Directory plugin to the latest available version (at least 1.25.4).
- Affected:
- up to 1.25.4
- Fixed in:
- 1.25.4
- Disclosed:
- Jun 28, 2022
Name Directory <= 1.25.2 - Cross-Site Scripting
medium
The Name Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘name’ parameter in versions up to, and including, 1.25.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...
- CVSS:
- 6.1
- Affected:
- up to 1.25.2
- Fixed in:
- 1.25.3
- Disclosed:
- May 8, 2022
CVE-2022-2072 on NVD →
Name Directory <= 1.17.4 - Cross-Site Request Forgery
high
Cross-site request forgery vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- CVSS:
- 8.8
- Affected:
- up to 1.17.4
- Fixed in:
- 1.18
- Disclosed:
- Feb 5, 2021
CVE-2021-20652 on NVD →
Name Directory [name-directory] < 1.18
unknown
[en] Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- Affected:
- up to 1.18
- Fixed in:
- 1.18
- Disclosed:
- Feb 5, 2021
CVE-2021-20652 on NVD →
Name Directory [name-directory] < 1.25.5
unknown
The plugin does not have CSRF check when adding/editing names, and is also lacking sanitisation as well as escaping in some of the fields, which could allow attackers to make a logged in admin edit arbitrary names and put XSS payloads in them.
- Affected:
- up to 1.25.5
- Fixed in:
- 1.25.5
Name Directory [name-directory] < 1.25.4
unknown
The plugin does not have CSRF checks in place when deleting Directories and Names, which could allow attackers to make a logged in admin delete them via a CSRF attack
- Affected:
- up to 1.25.4
- Fixed in:
- 1.25.4
Name Directory [name-directory] < 1.18
unknown
The plugin was affected by CSRF issues, allowing attackers to make a logged in administrator perform unwanted actions
- Affected:
- up to 1.18
- Fixed in:
- 1.18
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database