A Missing Authorization vulnerability exists in the Name Directory plugin for WordPress, affecting versions from n/a through 1.34.2. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. The CVSS score is 5.3, indicating a MEDIUM severity. Defenders and administrators using the Name Directory plugin for WordPress should assess their exposure and verify the configuration o [truncated]
A Cross-site Scripting vulnerability in the Name Directory plugin for WordPress, version 1.34.2 and earlier, allows stored XSS attacks. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Defenders responsible for WordPress site security, particularly those using the Name Directory plugin, should assess exposure and prioritize updating the plugin to prevent potential stored XSS [truncated]