Vulnerabilities / GeoDirectory / WPSEC-2026-0468

GeoDirectory <= 2.8.188 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Email Custom Field

Medium 5.4 CWE-79Fixed in 2.8.189
ID
WPSEC-2026-0468
Plugin
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (geodirectory)
Affected
all versions before 2.8.189
Remediation
Update to 2.8.189 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Low among sites WPSec scans, 2026-10-06
Attack surface
GeoDirectory on WPSec AttackSurface
Fix released
Published

Description

The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a listing's email custom field in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. The email value is saved with generic text sanitization only and, on display, passed through sanitize_email(), which still permits characters such as single quotes and backticks, before being placed unescaped inside a JavaScript string in the email link's onclick handler. This makes it possible for authenticated attackers with subscriber-level access and above, who can submit or edit their own listings from the front end, to inject arbitrary web scripts that execute when a user clicks the email link on the affected listing.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0