Stored Cross-Site Scripting in HivePress Business Directory Plugin for WordPress
CVE-2026-103520
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-103520?
The HivePress β Business Directory, Listings & Classified Ads Plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to a lack of proper input sanitization and output escaping. This vulnerability affects all versions up to and including 1.7.31. Authenticated attackers with subscriber-level access or higher can exploit this weakness by injecting arbitrary web scripts into pages. The exploitation occurs specifically when an administrator employs a custom text attribute formatted with the %value% token inside an HTML attribute, such as title="%value%", which can lead to malicious scripts executing in users' browsers upon accessing the affected pages.
Affected Version(s)
HivePress β Business Directory, Listings & Classified Ads Plugin 0 <= 1.7.31