Name Directory <= 1.32.0 - Unauthenticated Stored Cross-Site Scripting via Double HTML-Entity Encoding in Submission Form
Name Directory
Minimum safe version
1.33.0
Update to 1.33.0 or later to address 15 fixable vulnerabilities
Name Directory <= 1.32.1 - Unauthenticated Stored Cross-Site Scripting via 'name_directory_name'
CVE-2025-15283
CVE-2025-39454
CVE-2024-43938
Name Directory < 1.18 - Cross-Site Request Forgery (CSRF)
Name Directory < 1.25.4 - Arbitrary Directory/Name Deletion via CSRF
Name Directory < 1.25.5 - Stored Cross-Site Scripting via CSRF
CVE-2023-22692
Name Directory <= 1.25.4 - Unauthorized Settings Update
WordPress Name Directory plugin <= 1.25.4 - Stored Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-2072
CVE-2022-2071
WordPress Name Directory plugin <= 1.25.3 - Multiple Cross-Site Request Forgery (CSRF) vulnerabilities
CVE-2021-20652