Sceawere

Vulnerability Detail

CVE-2026-96647UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Listdom Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
15h ago
Vendor
webilia
Product
Listdom: AI-powered Business Directory with Classifieds Ads Listings
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up to, and including, 6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users because the listing-creation branch of the AJAX handler omits a capability check, and the required nonce is publicly emitted on any page containing the [listdom-dashboard] shortcode.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-02T08:17:04.643Z",
  "pubdate": "2026-10-02T08:17:04.643Z",
  "executiveSummary": "The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in all versions up to and including 6.1.1.\nThe vulnerability arises from improper sanitization of the 'lsd[remark]' parameter within the listing creation AJAX handler.\nAn attacker can inject arbitrary malicious JavaScript into the application, which executes in the context of a victim's browser session upon viewing the compromised page.\nWhile the vulnerability is theoretically restricted to users with contributor-level access, the lack of a capability check in the AJAX handler and the public availability of the required security nonce on pages containing the [listdom-dashboard] shortcode allow even unprivileged Subscriber-level users to exploit the flaw.\nSuccessful exploitation allows for session hijacking, unauthorized actions on behalf of the victim, and potential administrative account compromise if a privileged user views the injected content.\nThis represents a significant security risk, necessitating immediate update or mitigation to prevent unauthorized script execution within the WordPress environment.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the Listdom plugin to adequately sanitize user-supplied input provided through the 'lsd[remark]' parameter during the listing creation process. Furthermore, the application fails to perform proper output escaping when rendering this data in the front-end or administrative dashboard.\nThe vulnerability exists within the plugin's AJAX handler responsible for processing business listing submissions. Analysis indicates that the specific branch of the handler tasked with creating listings lacks a mandatory capability check, which is a critical security omission in the WordPress plugin development lifecycle.\nExploitation is facilitated by the exposure of the required security nonce. WordPress nonces are intended to prevent Cross-Site Request Forgery (CSRF); however, in this instance, the nonce is publicly emitted on any page containing the [listdom-dashboard] shortcode. An authenticated attacker, regardless of their role (specifically targeting Subscriber-level users), can scrape this nonce from the page source.\nThe attack flow proceeds as follows: First, the attacker navigates to a page where the [listdom-dashboard] shortcode is present to acquire a valid security nonce. Second, the attacker crafts a malicious AJAX request directed at the Listdom listing creation endpoint, including the valid nonce and the 'lsd[remark]' parameter populated with a JavaScript payload (e.g., <script>alert(document.cookie)</script>). Third, because the AJAX handler does not perform server-side validation of the user's capabilities, the server accepts the malicious input and persists it directly into the WordPress database.\nWhen a legitimate user or administrator navigates to a page rendering the 'lsd[remark]' field, the malicious script is executed by their browser. This allows for arbitrary code execution within the security context of the victim. The impact includes the theft of session tokens, redirection to malicious websites, unauthorized modification of site content, and potential privilege escalation by targeting administrative sessions."
}
CVE-2026-96647: Listdom Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.4) | Sceawere