Stored Cross-Site Scripting Vulnerability in Listdom Plugin for WordPress
CVE-2026-19796

7.2HIGH

What is CVE-2026-19796?

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress has a vulnerability that allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) through the 'lsd[displ][style]' parameter. This issue arises from inadequate input sanitization and output escaping present in all versions up to and including 5.8.1. Exploiting this vulnerability necessitates that the Listdom Pro add-on is enabled, alongside the 'Display Options Per Listing' setting, both of which are not default configurations. Consequently, attackers could inject malicious scripts into pages, which would execute when a user accesses the compromised page, potentially compromising user data and site integrity.

Affected Version(s)

Listdom: AI-powered Business Directory with Classifieds Ads Listings 0 <= 5.8.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.