Impact
The vulnerability allows a logged‑in user with subscriber permissions or higher to inject arbitrary HTML or JavaScript into the "Contact Email" custom field of a new listing. When a listing is approved by an administrator and the custom field is rendered on the public listing page, the injected scripts will run in the browser of any visitor. This can lead to defacement, data theft, or session hijacking for users viewing the page. The injected code is stored, so the impact persists until the listing is removed or the field is sanitized.
Affected Systems
All WordPress sites running the GeoDirectory – WP Business Directory Plugin (Classified Listings Directory) version 2.8.188 or earlier are affected. The plugin must have been configured to display the Contact Email custom field on the public single‑listing page. The vulnerability applies to any subscriber‑level user or higher who can submit listings.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to be authenticated with at least subscriber access, submit a listing that contains malicious content in the Contact Email field, and rely on an administrator to approve the listing. Upon viewing the approved listing, the attacker’s script executes in the context of the visitor’s browser, allowing malicious actions such as credential theft or further lateral movement.
OpenCVE Enrichment