{
 "id": "WPSEC-2026-0468",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0468/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0468/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0468/index.md",
 "title": "GeoDirectory <= 2.8.188 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Email Custom Field",
 "description": "The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a listing's email custom field in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. The email value is saved with generic text sanitization only and, on display, passed through sanitize_email(), which still permits characters such as single quotes and backticks, before being placed unescaped inside a JavaScript string in the email link's onclick handler. This makes it possible for authenticated attackers with subscriber-level access and above, who can submit or edit their own listings from the front end, to inject arbitrary web scripts that execute when a user clicks the email link on the affected listing.",
 "plugin": {
  "slug": "geodirectory",
  "name": "GeoDirectory",
  "full_name": "GeoDirectory – WP Business Directory Plugin and Classified Listings Directory",
  "wordpress_org": "https://wordpress.org/plugins/geodirectory/",
  "advisories_url": "https://wpsec.com/vuln/plugin/geodirectory/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/geodirectory"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.8.189",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.8.189"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.8.189",
 "remediation": "Update to 2.8.189 or later.",
 "fix_released": "2026-10-05T09:03:31+00:00",
 "published": "2026-10-06T18:46:14+00:00",
 "updated": "2026-10-06T18:33:32.327477+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0468/",
  "https://plugins.svn.wordpress.org/geodirectory/tags/2.8.189/",
  "https://wordpress.org/plugins/geodirectory/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/geodirectory",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Low",
  "as_of": "2026-10-06"
 }
}