Stored Cross-Site Scripting Vulnerability in CM Business Directory Plugin by WordPress
CVE-2025-10178

6.4MEDIUM

What is CVE-2025-10178?

The CM Business Directory plugin for WordPress is subject to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'cmbd_featured_image' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages, posing a risk of executing these scripts for users who visit the compromised pages. This vulnerability exists in all versions of the plugin up to and including 1.5.2.

Affected Version(s)

CM Business Directory – Optimise and showcase local business * <= 1.5.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Youcef Hamdani
.
CVE-2025-10178 : Stored Cross-Site Scripting Vulnerability in CM Business Directory Plugin by WordPress