plugin

Name Directory Vulnerabilities

24 known security issues reported for the Name Directory WordPress plugin. Most recent disclosed Mar 12, 2026.

6 high 5 medium

Running Name Directory on your site? Check whether your installed version is affected.

Scan your site free

Name Directory - Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' vulnerability

high

Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' vulnerability

CVSS:
7.1
Affected:
up to 1.32.1
Fixed in:
1.33.0
Disclosed:
Mar 12, 2026

Name Directory <= 1.32.1 - Unauthenticated Stored Cross-Site Scripting via 'name_directory_name'

high

The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' parameter in all versions up to, and including, 1.32.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
7.2
Affected:
up to 1.32.1
Fixed in:
1.33.0
Disclosed:
Mar 10, 2026

CVE-2026-3178 on NVD →

Name Directory <= 1.32.0 - Unauthenticated Stored Cross-Site Scripting via Double HTML-Entity Encoding in Submission Form

high

The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via double HTML-entity encoding in all versions up to, and including, 1.32.0. This is due to the plugin's sanitization function calling `html_entity_decode()` before `wp_kses()`, and then calling `html_entity_decode()` again on output....

CVSS:
7.2
Affected:
up to 1.32.0
Fixed in:
1.32.1
Disclosed:
Feb 9, 2026

CVE-2026-1866 on NVD →

Name Directory [name-directory] < 1.31.0

unknown

[en] The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and 'name_directory_description' parameters in all versions up to, and including, 1.30.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attacke...

Affected:
up to 1.31.0
Fixed in:
1.31.0
Disclosed:
Jan 14, 2026

CVE-2025-15283 on NVD →

Name Directory <= 1.30.3 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters

high

The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and 'name_directory_description' parameters in all versions up to, and including, 1.30.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

CVSS:
7.2
Affected:
up to 1.30.3
Fixed in:
1.31.0
Disclosed:
Jan 13, 2026

CVE-2025-15283 on NVD →

Name Directory [name-directory] < 1.30.1

unknown

[en] Missing Authorization vulnerability in Jeroen Peters Name Directory.This issue affects Name Directory: from n/a through 1.30.0.

Affected:
up to 1.30.1
Fixed in:
1.30.1
Disclosed:
May 19, 2025

CVE-2025-39454 on NVD →

Name Directory <= 1.30.0 - Missing Authorization

medium

The Name Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.30.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.30.0
Fixed in:
1.30.1
Disclosed:
Apr 17, 2025

CVE-2025-39454 on NVD →

Name Directory [name-directory] < 1.29.1

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jeroen Peters Name Directory allows Reflected XSS.This issue affects Name Directory: from n/a through 1.29.0.

Affected:
up to 1.29.1
Fixed in:
1.29.1
Disclosed:
Sep 17, 2024

CVE-2024-43938 on NVD →

Name Directory <= 1.29.0 - Reflected Cross-Site Scripting

medium

The Name Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.29.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...

CVSS:
6.1
Affected:
up to 1.29.0
Fixed in:
1.29.1
Disclosed:
Aug 26, 2024

CVE-2024-43938 on NVD →

Name Directory [name-directory] < 1.27.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Jeroen Peters Name Directory plugin <= 1.27.1 versions.

Affected:
up to 1.27.2
Fixed in:
1.27.2
Disclosed:
May 22, 2023

CVE-2023-22692 on NVD →

Name Directory <= 1.27.1 - Cross Site Request Forgery

medium

The Name Directory plugin for WordPress is vulnerable to Cross Site Request Forgery in versions up to, and including, 1.27.1. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can trick a site administra...

CVSS:
4.3
Affected:
up to 1.27.1
Fixed in:
1.27.2
Disclosed:
Jan 23, 2023

CVE-2023-22692 on NVD →

Name Directory [name-directory] < 1.25.4

unknown

[en] The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.

Affected:
up to 1.25.4
Fixed in:
1.25.4
Disclosed:
Jul 25, 2022

CVE-2022-2071 on NVD →

Name Directory [name-directory] < 1.25.4

unknown

[en] The Name Directory WordPress plugin before 1.25.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. Furthermore, as the payload is also saved into the database after the request, it leads to a Stored XSS as well

Affected:
up to 1.25.4
Fixed in:
1.25.4
Disclosed:
Jul 25, 2022

CVE-2022-2072 on NVD →

Name Directory [name-directory] < 1.25.5

unknown

Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability discovered by WPScanTeam in WordPress Name Directory plugin (versions <= 1.25.4). Update the WordPress Name Directory plugin to the latest available version (at least 1.25.5).

Affected:
up to 1.25.5
Fixed in:
1.25.5
Disclosed:
Jul 18, 2022

Name Directory <= 1.25.4 - Unauthorized Settings Update

medium

The Name Directory plugin for WordPress is vulnerable to unauthorized settings update due to insufficient permissions checking on the name_directory_options() function in versions up to, and including, 1.25.4. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to perform....

CVSS:
6.3
Affected:
up to 1.25.4
Fixed in:
1.25.5
Disclosed:
Jul 15, 2022

Name Directory [name-directory] < 1.25.5

unknown

The Name Directory plugin for WordPress is vulnerable to unauthorized settings update due to insufficient permissions checking on the name_directory_options() function in versions up to, and including, 1.25.4. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to perform....

Affected:
up to 1.25.5
Fixed in:
1.25.5
Disclosed:
Jul 15, 2022

Name Directory <= 1.25.3 - Cross-Site Request Forgery

high

The Name Directory plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.25.3. This is due to missing or incorrect nonce validation when editing, deleting or naming directories. This makes it possible for unauthenticated attackers to trigger the above actions via forged re...

CVSS:
8.8
Affected:
up to 1.25.3
Fixed in:
1.25.4
Disclosed:
Jun 28, 2022

CVE-2022-2071 on NVD →

Name Directory [name-directory] < 1.25.4

unknown

Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were discovered in the WordPress Name Directory plugin (versions <= 1.25.3). Update the WordPress Name Directory plugin to the latest available version (at least 1.25.4).

Affected:
up to 1.25.4
Fixed in:
1.25.4
Disclosed:
Jun 28, 2022

Name Directory <= 1.25.2 - Cross-Site Scripting

medium

The Name Directory plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘name’ parameter in versions up to, and including, 1.25.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 1.25.2
Fixed in:
1.25.3
Disclosed:
May 8, 2022

CVE-2022-2072 on NVD →

Name Directory <= 1.17.4 - Cross-Site Request Forgery

high

Cross-site request forgery vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVSS:
8.8
Affected:
up to 1.17.4
Fixed in:
1.18
Disclosed:
Feb 5, 2021

CVE-2021-20652 on NVD →

Name Directory [name-directory] < 1.18

unknown

[en] Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

Affected:
up to 1.18
Fixed in:
1.18
Disclosed:
Feb 5, 2021

CVE-2021-20652 on NVD →

Name Directory [name-directory] < 1.25.5

unknown

The plugin does not have CSRF check when adding/editing names, and is also lacking sanitisation as well as escaping in some of the fields, which could allow attackers to make a logged in admin edit arbitrary names and put XSS payloads in them.

Affected:
up to 1.25.5
Fixed in:
1.25.5

Name Directory [name-directory] < 1.25.4

unknown

The plugin does not have CSRF checks in place when deleting Directories and Names, which could allow attackers to make a logged in admin delete them via a CSRF attack

Affected:
up to 1.25.4
Fixed in:
1.25.4

Name Directory [name-directory] < 1.18

unknown

The plugin was affected by CSRF issues, allowing attackers to make a logged in administrator perform unwanted actions

Affected:
up to 1.18
Fixed in:
1.18

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database