Directorist: AI-Powered Business Directory, Listings & Classified Ads <= 8.10 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Map Info Window Phone Number and Coordinates

Medium 6.4 CWE-79Fixed in 8.10.1
ID
WPSEC-2026-0486
Plugin
Directorist: AI-Powered Business Directory, Listings & Classified Ads (directorist)
Affected
all versions before 8.10.1
Remediation
Update to 8.10.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Directorist: AI-Powered Business Directory, Listings & Classified Ads on WPSec AttackSurface
Fix released
Published

Description

The Directorist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the listing phone number and map coordinates shown in the single listing map info window in all versions up to, and including, 8.10. This is due to insufficient output escaping of these values when they are placed into link attributes and content. This makes it possible for authenticated attackers with subscriber-level access and above who can submit listings (or unauthenticated attackers when guest submission is enabled) to inject arbitrary web scripts that execute when a user views the listing's map info window.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0