Sceawere

Vulnerability Detail

CVE-2026-104993UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in GeoDirectory Plugin

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
3h ago
Vendor
paoltaia
Product
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator has added and configured the Contact Email custom field to render on the public single-listing output page, and that the administrator subsequently approves the attacker's submitted listing.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T05:16:39.880Z",
  "pubdate": "2026-10-10T05:16:39.880Z",
  "executiveSummary": "The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability in all versions up to and including 2.8.188.\nThis security flaw stems from inadequate input sanitization and output escaping within the 'email' custom field (identified by the htmlvar_name parameter).\nAn authenticated attacker with at least subscriber-level privileges can inject malicious JavaScript payloads into listing submissions.\nThe vulnerability manifests when an administrator configures the 'Contact Email' field for public display and subsequently approves a malicious listing submission.\nSuccessful exploitation allows for the execution of arbitrary web scripts in the browser of any user viewing the affected listing page.\nThis poses a significant risk as it can lead to session hijacking, unauthorized actions performed on behalf of authenticated users, or the redirection of visitors to malicious websites.\nThe requirement for administrative approval acts as a gatekeeping mechanism but does not mitigate the inherent danger once the payload is rendered on the frontend.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the GeoDirectory plugin to properly sanitize user-supplied data submitted via the 'email' custom field and the subsequent failure to escape this data when rendered in the Document Object Model (DOM) of the public-facing single-listing pages.\nWhen a user with subscriber-level permissions submits a listing, they can input a payload containing malicious script tags or event handlers into the 'Contact Email' field. Because the plugin does not implement sufficient input validation or server-side sanitization, the payload is stored verbatim in the WordPress database.\nThe attack flow proceeds as follows: First, the attacker creates or edits a listing, injecting the XSS payload into the 'email' field. Second, the attacker submits the listing for review. Third, an administrator with the necessary privileges reviews the submission and approves it, which publishes the listing to the live site. Finally, when any visitor or administrator views the public single-listing page, the application retrieves the malicious payload from the database and renders it into the HTML document without proper contextual output escaping.\nSince the script is injected directly into the HTML context of the page, the browser interprets the payload as legitimate code, leading to arbitrary JavaScript execution in the context of the visitor's session. This allows the attacker to bypass standard security controls, perform unauthorized actions on behalf of the victim, exfiltrate sensitive cookies, or manipulate the page content to perform phishing attacks.\nThis vulnerability is classified as Stored XSS because the payload resides in the persistent storage of the web application. Because the execution occurs on the public frontend, any user—including unauthenticated visitors—who views the compromised page triggers the payload, significantly increasing the potential impact of the vulnerability. The security flaw is present across all versions of the GeoDirectory plugin up to 2.8.188, affecting the handling of custom field data associated with the 'htmlvar_name' parameter."
}
CVE-2026-104993: Stored XSS in GeoDirectory Plugin (MEDIUM Severity, CVSS: 6.4) | Sceawere