Stored XSS Vulnerability in HivePress Business Directory Plugin for WordPress
CVE-2026-107657
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-107657?
The HivePress Business Directory Plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This issue arises due to inadequate input sanitization and output escaping on the '<custom user attribute field name, e.g. profile_test>' parameter. An unauthenticated attacker can exploit this flaw by injecting malicious web scripts into pages. The vulnerability can be triggered when an administrator creates a text-type custom user attribute formatted in a way that includes variables in an HTML attribute context, which is typical in the plugin’s configuration. As such, when front-end user profiles are enabled, these scripts can execute in users' browsers upon visiting the compromised pages, jeopardizing user data and site integrity.
Affected Version(s)
HivePress – Business Directory, Listings & Classified Ads Plugin 0 <= 1.7.31