Stored Cross-Site Scripting Vulnerability in CM Business Directory Plugin by WordPress
CVE-2025-10178
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 September 2025
What is CVE-2025-10178?
The CM Business Directory plugin for WordPress is subject to a Stored Cross-Site Scripting vulnerability that arises from inadequate input sanitization and output escaping of user-supplied attributes in the 'cmbd_featured_image' shortcode. This flaw allows authenticated attackers with contributor-level access or higher to inject malicious scripts into web pages, posing a risk of executing these scripts for users who visit the compromised pages. This vulnerability exists in all versions of the plugin up to and including 1.5.2.
Affected Version(s)
CM Business Directory – Optimise and showcase local business * <= 1.5.2