Stored Cross-Site Scripting Vulnerability in Listdom Plugin for WordPress
CVE-2026-19796
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-19796?
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress has a vulnerability that allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) through the 'lsd[displ][style]' parameter. This issue arises from inadequate input sanitization and output escaping present in all versions up to and including 5.8.1. Exploiting this vulnerability necessitates that the Listdom Pro add-on is enabled, alongside the 'Display Options Per Listing' setting, both of which are not default configurations. Consequently, attackers could inject malicious scripts into pages, which would execute when a user accesses the compromised page, potentially compromising user data and site integrity.
Affected Version(s)
Listdom: AI-powered Business Directory with Classifieds Ads Listings 0 <= 5.8.1