# GeoDirectory <= 2.8.188 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Email Custom Field

- **ID:** WPSEC-2026-0468
- **Plugin:** GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (`geodirectory`), https://wordpress.org/plugins/geodirectory/
- **Affected versions:** all versions before 2.8.189
- **Fixed in:** 2.8.189 (Update to 2.8.189 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Low (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/geodirectory
- **Fix released:** 2026-10-05
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0468/

## Description

The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a listing's email custom field in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. The email value is saved with generic text sanitization only and, on display, passed through sanitize_email(), which still permits characters such as single quotes and backticks, before being placed unescaped inside a JavaScript string in the email link's onclick handler. This makes it possible for authenticated attackers with subscriber-level access and above, who can submit or edit their own listings from the front end, to inject arbitrary web scripts that execute when a user clicks the email link on the affected listing.

## References

- https://wpsec.com/vuln/WPSEC-2026-0468/
- https://plugins.svn.wordpress.org/geodirectory/tags/2.8.189/
- https://wordpress.org/plugins/geodirectory/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0468/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
