Impact
Unauthenticated Cross Site Scripting (XSS) exists in GeoDirectory plugin versions up to 2.8.173 for WordPress. This flaw allows an attacker to inject malicious scripts that are executed in the browsers of site visitors. The weakness is a classic reflected or stored XSS issue as identified by CWE-79.
Affected Systems
The vulnerable product is the WordPress GeoDirectory plugin (Paolo:GeoDirectory) with affected releases up to and including 2.8.173. All installations running these or earlier versions are susceptible, regardless of the WordPress core version or hosting environment.
Risk and Exploitability
The CVSS score of 7.1 indicates medium to high severity, and the vulnerability can be exploited without any authentication, relying solely on a victim's browser interaction. EPSS data is not available. The vulnerability is not listed in CISA KEV, indicating no current evidence of widespread exploitation.
OpenCVE Enrichment