
CVE-2024-13182 – WP Directorybox Manager <= 2.5 - Authentication Bypass
https://notcve.org/view.php?id=CVE-2024-13182
12 Feb 2025 — The WP Directorybox Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_parse_request' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator. • http://localhost:1337/wp-content/plugins/wp-directorybox-manager/elements/login/cs-social-login/cs-social-login.php#L43 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •

CVE-2025-0316 – WP Directorybox Manager <= 2.5 - Authentication Bypass
https://notcve.org/view.php?id=CVE-2025-0316
08 Feb 2025 — The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.5. This is due to incorrect authentication in the 'wp_dp_enquiry_agent_contact_form_submit_callback' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username. • https://themeforest.net/item/directory-multipurpose-wordpress-theme/10480929 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •