Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 25 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paoltaia
Paoltaia geodirectory – Wp Business Directory Plugin And Classified Listings Directory Wordpress Wordpress wordpress |
|
| Vendors & Products |
Paoltaia
Paoltaia geodirectory – Wp Business Directory Plugin And Classified Listings Directory Wordpress Wordpress wordpress |
Fri, 25 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the AJAX save handler validates only post authorship and a nonce with no additional capability check, allowing any subscriber-level user who owns a listing to exploit this vulnerability. | |
| Title | GeoDirectory <= 2.8.183 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'business_hours' Parameter | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-25T10:38:10.167Z
Reserved: 2026-09-23T16:04:55.869Z
Link: CVE-2026-96766
Updated: 2026-09-25T10:38:06.070Z
Status : Deferred
Published: 2026-09-25T07:16:57.017
Modified: 2026-09-25T13:08:08.163
Link: CVE-2026-96766
No data.
OpenCVE Enrichment
Updated: 2026-09-25T10:15:07Z