Impact
The Listdom WordPress plugin stores an XSS payload in the lsd[displ][style] parameter without sanitizing input, allowing any attacker to inject and persist malicious JavaScript that executes for every visitor of the affected site. This stored cross‑site scripting can steal credentials, hijack sessions, deface pages, or deliver other client‑side attacks, as defined by CWE‑79, and breaches confidentiality, integrity, and availability for users.
Affected Systems
All Webilia Listdom installations up to and including version 5.8.1 are vulnerable, provided the Listdom Pro add‑on is active and the 'Display Options Per Listing' displ setting is enabled. Systems lacking either component are not affected by this flaw.
Risk and Exploitability
The CVSS score of 7.2 classifies the flaw as high‑severity, and the lack of an EPSS score does not diminish the risk in a typical WordPress deployment. Because the attack requires no authentication and the malicious content is stored, any visitor of the site may be impacted after a single exploit. The vulnerability is listed in the vendor advisories but not yet in the CISA KEV catalog, indicating that it has not yet been observed in widespread exploitation, though the conditions make it easy to use if the plugin is present.
OpenCVE Enrichment