CVE-2026-104993
Description
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator has added and configured the Contact Email custom field to render on the public single-listing output page, and that the administrator subsequently approves the attacker's submitted listing.
Affected products
2- Range: <=2.8.188
- Range: <=2.8.188
Patches
Vulnerability mechanics
References
5- plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.188/includes/class-geodir-post-data.phpnvd
- plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.188/includes/custom-fields/output-functions.phpnvd
- plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.188/includes/post-functions.phpnvd
- plugins.trac.wordpress.org/changeset/3728472/geodirectory/trunk/includes/custom-fields/output-functions.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/1356ec70-4264-4687-8082-7d87a8978082nvd
News mentions
0No linked articles in our index yet.