Description
Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Name Directory: from n/a through 1.34.2.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch
AI Analysis

Impact

The Jeroen Peters Name Directory plugin for WordPress contains a missing authorization check that allows arbitrary shortcode execution. An attacker who can supply content to the plugin may inject and run shortcodes that execute PHP code on the host, potentially compromising the site’s confidentiality, integrity, and availability. This weakness is identified as CWE-862: Missing Permissions.

Affected Systems

The vulnerable product is the Name Directory plugin for WordPress, developed by Jeroen Peters. All releases from the earliest available version through 1.34.2 are affected. No vulnerability details are available for versions newer than 1.34.2.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Because the flaw is a missing permissions check, it can likely be exploited by any user able to submit content to the plugin, possibly even unauthenticated users, as inferred from the lack of authentication controls.

Generated by OpenCVE AI on October 5, 2026 at 10:37 UTC.

Remediation

Vendor Solution

Update the WordPress Name Directory plugin to the latest available version (at least 1.34.3).


OpenCVE Recommended Actions

  • Update the Name Directory plugin to version 1.34.3 or later.
  • Restrict shortcode execution so that only administrators retain the unfiltered_html capability and other privileged roles are prevented from inserting arbitrary shortcodes.
  • Audit existing content for unexpected shortcodes and monitor logs for suspicious injection attempts.

Generated by OpenCVE AI on October 5, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Name Directory: from n/a through 1.34.2.
Title WordPress Name Directory plugin <= 1.34.2 - Arbitrary Shortcode Execution vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T15:29:19.729Z

Reserved: 2026-10-02T00:22:13.105Z

Link: CVE-2026-104397

cve-icon Vulnrichment

Updated: 2026-10-05T14:50:59.711Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T09:17:07.933

Modified: 2026-10-06T15:04:25.990

Link: CVE-2026-104397

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:45:21Z

Weaknesses