Stored Cross-Site Scripting in GeoDirectory WP Business Directory Plugin by AIT
CVE-2026-96766

6.4MEDIUM

What is CVE-2026-96766?

The GeoDirectory – WP Business Directory Plugin is affected by a vulnerability that allows authenticated attackers, with subscriber-level access and above, to exploit insufficient input sanitization and output escaping. The 'business_hours' parameter is particularly vulnerable, allowing attackers to inject arbitrary scripts that execute when users access compromised pages. This issue arises because the AJAX save handler only validates authorship and a nonce, lacking additional capability checks, which enables any subscriber-level user who has a listing to carry out the exploitation.

Affected Version(s)

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory 0 <= 2.8.183

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuto Hyakumoto
.