plugin

Wp Directorybox Manager Vulnerabilities

2 known security issues reported for the Wp Directorybox Manager WordPress plugin. Most recent disclosed Feb 12, 2025.

2 critical

Running Wp Directorybox Manager on your site? Check whether your installed version is affected.

Scan your site free

WP Directorybox Manager <= 2.5 - Authentication Bypass

critical

The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an ad...

CVSS:
9.8
Affected:
up to 2.5
Fix:
No patched version reported
Disclosed:
Feb 12, 2025

CVE-2024-13182 on NVD →

WP Directorybox Manager <= 2.5 - Authentication Bypass

critical

The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in as any existing user o...

CVSS:
9.8
Affected:
up to 2.5
Fix:
No patched version reported
Disclosed:
Feb 8, 2025

CVE-2025-0316 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database