Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3.
Published: 2026-02-19
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting (XSS)
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting (XSS) flaw that allows an attacker to inject malicious script code into the CM Business Directory plugin. When the input is later rendered in the web page, the script executes in the context of visitors’ browsers, potentially enabling theft of session cookies, credential logging, or other client‑side attacks. The flaw is identified as CWE‑79 and is rated with a CVSS score of 4.8, indicating a moderate impact within the affected environment.

Affected Systems

CreativeMindsSolutions CM Business Directory plugin versions up to and including 1.5.3 are affected. The issue exists in all releases from the earliest available version through version 1.5.3.

Risk and Exploitability

The CVSS score of 4.8 reflects the potential for information disclosure and client‑side compromise, but the EPSS score of less than 1% suggests that active exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit the flaw by submitting malicious input via the plugin’s interface, which is then stored and displayed to site users. Because the stored payload runs from the website, any user who views the affected content will be at risk. The lack of a published patch sequence means administrators should promptly review updates or mitigate risk through disabling or restricting the plugin.

Generated by OpenCVE AI on April 16, 2026 at 00:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update CM Business Directory to a version newer than 1.5.3 when an official patch is released.
  • If a later version is unavailable, consider disabling the plugin or removing it entirely from the site.
  • As an interim measure, restrict the plugin’s input capabilities to administrators only to limit the attack surface.

Generated by OpenCVE AI on April 16, 2026 at 00:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 03 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Creativemindssolutions
Creativemindssolutions cm Business Directory
Wordpress
Wordpress wordpress
Vendors & Products Creativemindssolutions
Creativemindssolutions cm Business Directory
Wordpress
Wordpress wordpress

Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Business Directory cm-business-directory allows Stored XSS.This issue affects CM Business Directory: from n/a through <= 1.5.3.
Title WordPress CM Business Directory plugin <= 1.5.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Creativemindssolutions Cm Business Directory
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-24T18:07:16.158Z

Reserved: 2026-01-28T09:50:57.104Z

Link: CVE-2026-25004

cve-icon Vulnrichment

Updated: 2026-03-03T18:08:42.541Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T09:16:14.210

Modified: 2026-04-23T15:36:59.493

Link: CVE-2026-25004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T00:45:15Z

Weaknesses