Stored Cross-Site Scripting in GeoDirectory WP Business Directory Plugin by AIT
CVE-2026-96766
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-96766?
The GeoDirectory β WP Business Directory Plugin is affected by a vulnerability that allows authenticated attackers, with subscriber-level access and above, to exploit insufficient input sanitization and output escaping. The 'business_hours' parameter is particularly vulnerable, allowing attackers to inject arbitrary scripts that execute when users access compromised pages. This issue arises because the AJAX save handler only validates authorship and a nonce, lacking additional capability checks, which enables any subscriber-level user who has a listing to carry out the exploitation.
Affected Version(s)
GeoDirectory β WP Business Directory Plugin and Classified Listings Directory 0 <= 2.8.183