CVE-2025-10178
Description
The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featured_image' shortcode in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in CM Business Directory plugin for WordPress via 'cmbd_featured_image' shortcode, allowing authenticated contributors to inject scripts.
The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 1.5.2. The vulnerability exists in the 'cmbd_featured_image' shortcode, which does not sufficiently sanitize user-supplied attributes or escape output, allowing attackers to inject arbitrary web scripts [1].
To exploit this vulnerability, an attacker must be authenticated with at least contributor-level access. By crafting a malicious attribute in the shortcode, the attacker can inject JavaScript that becomes stored on the page. When other users, including administrators, view the affected page, the injected script executes in the context of their browser [1].
Successful exploitation could allow an attacker to perform actions like stealing session cookies, defacing the site, redirecting users to malicious sites, or performing actions on behalf of the victim. The impact is limited by the contributor role requirement, but any user with that role could potentially compromise the site [1].
As of the publication date, no patch is mentioned. Users are advised to update the plugin to the latest available version once a fix is released, and to restrict contributor-level access to trusted users only [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.5.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- plugins.trac.wordpress.org/browser/cm-business-directory/tags/1.5.2/frontend/cm-business-directory-business-page-sc.phpnvd
- plugins.trac.wordpress.org/browser/cm-business-directory/trunk/frontend/cm-business-directory-business-page-sc.phpnvd
- plugins.trac.wordpress.org/browser/cm-business-directory/trunk/frontend/cm-business-directory-business-page-sc.phpnvd
- wordpress.org/plugins/cm-business-directory/nvd
- www.wordfence.com/threat-intel/vulnerabilities/id/2c1ecd71-57ed-44ba-a007-3b96b98d3bf7nvd
News mentions
0No linked articles in our index yet.