Sceawere
Vulnerability Detail
CVE-2026-96647UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Listdom Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 15h ago
- Vendor
- webilia
- Product
- Listdom: AI-powered Business Directory with Classifieds Ads Listings
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up to, and including, 6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users because the listing-creation branch of the AJAX handler omits a capability check, and the required nonce is publicly emitted on any page containing the [listdom-dashboard] shortcode.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-02T08:17:04.643Z",
"pubdate": "2026-10-02T08:17:04.643Z",
"executiveSummary": "The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability in all versions up to and including 6.1.1.\nThe vulnerability arises from improper sanitization of the 'lsd[remark]' parameter within the listing creation AJAX handler.\nAn attacker can inject arbitrary malicious JavaScript into the application, which executes in the context of a victim's browser session upon viewing the compromised page.\nWhile the vulnerability is theoretically restricted to users with contributor-level access, the lack of a capability check in the AJAX handler and the public availability of the required security nonce on pages containing the [listdom-dashboard] shortcode allow even unprivileged Subscriber-level users to exploit the flaw.\nSuccessful exploitation allows for session hijacking, unauthorized actions on behalf of the victim, and potential administrative account compromise if a privileged user views the injected content.\nThis represents a significant security risk, necessitating immediate update or mitigation to prevent unauthorized script execution within the WordPress environment.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Listdom plugin to adequately sanitize user-supplied input provided through the 'lsd[remark]' parameter during the listing creation process. Furthermore, the application fails to perform proper output escaping when rendering this data in the front-end or administrative dashboard.\nThe vulnerability exists within the plugin's AJAX handler responsible for processing business listing submissions. Analysis indicates that the specific branch of the handler tasked with creating listings lacks a mandatory capability check, which is a critical security omission in the WordPress plugin development lifecycle.\nExploitation is facilitated by the exposure of the required security nonce. WordPress nonces are intended to prevent Cross-Site Request Forgery (CSRF); however, in this instance, the nonce is publicly emitted on any page containing the [listdom-dashboard] shortcode. An authenticated attacker, regardless of their role (specifically targeting Subscriber-level users), can scrape this nonce from the page source.\nThe attack flow proceeds as follows: First, the attacker navigates to a page where the [listdom-dashboard] shortcode is present to acquire a valid security nonce. Second, the attacker crafts a malicious AJAX request directed at the Listdom listing creation endpoint, including the valid nonce and the 'lsd[remark]' parameter populated with a JavaScript payload (e.g., <script>alert(document.cookie)</script>). Third, because the AJAX handler does not perform server-side validation of the user's capabilities, the server accepts the malicious input and persists it directly into the WordPress database.\nWhen a legitimate user or administrator navigates to a page rendering the 'lsd[remark]' field, the malicious script is executed by their browser. This allows for arbitrary code execution within the security context of the victim. The impact includes the theft of session tokens, redirection to malicious websites, unauthorized modification of site content, and potential privilege escalation by targeting administrative sessions."
}