Stored Cross-Site Scripting in GeoDirectory Business Directory Plugin for WordPress
CVE-2026-93897
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-93897?
The GeoDirectory β WP Business Directory Plugin and Classified Listings Directory plugin for WordPress has a security vulnerability due to inadequate input sanitization and output escaping for text-type custom fields, such as a 'phone' field. Authenticated attackers with subscriber-level access can exploit this vulnerability to inject malicious scripts via the AJAX geodir_save_post endpoint. By using entity-encoded angle brackets, they can store harmful payloads that execute whenever a user accesses affected pages. This poses a significant risk to users and data integrity.
Affected Version(s)
GeoDirectory β WP Business Directory Plugin and Classified Listings Directory 0 <= 2.8.181