Stored XSS Vulnerability in HivePress Business Directory Plugin for WordPress
CVE-2026-107657

7.2HIGH

What is CVE-2026-107657?

The HivePress Business Directory Plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises due to inadequate input sanitization and output escaping on the '<custom user attribute field name, e.g. profile_test>' parameter. An unauthenticated attacker can exploit this flaw by injecting malicious web scripts into pages. The vulnerability can be triggered when an administrator creates a text-type custom user attribute formatted in a way that includes variables in an HTML attribute context, which is typical in the plugin’s configuration. As such, when front-end user profiles are enabled, these scripts can execute in users' browsers upon visiting the compromised pages, jeopardizing user data and site integrity.

Affected Version(s)

HivePress – Business Directory, Listings & Classified Ads Plugin 0 <= 1.7.31

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrien Brunner
.