Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
CVE-2025-15677
Description
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/bb6daced-3ee3-4ec7-a221-9981cd85285a/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.