Impact
Contributor Cross Site Scripting (XSS) is disclosed for GeoDirectory plugin versions 2.8.172 and earlier. The CVE description does not detail the exact mechanism, but XSS typically means that a malicious script can be injected and executed in the browsers of users who view content processed by the plugin. The flaw is classified as CWE‑79, indicating that data submitted or displayed by the plugin may not be properly validated or escaped before rendering. Based on the nature of the flaw, it is inferred that the injection of JavaScript could affect visitors of the site.
Affected Systems
WordPress sites that have installed the GeoDirectory plugin up to version 2.8.172 are affected. The vendor is Paolo. Any WordPress installation using this plugin and its legacy versions is at risk until the plugin is upgraded.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS data is unavailable and the vulnerability is not included in the CISA KEV catalog. Based on the CVE title and common behavior of XSS flaws, a likely attack vector involves unsanitized input or output when a user submits or views content via the plugin. The impact is confined to the victim’s browser session and does not elevate privileges or compromise the server itself. These inferences are drawn from the typical characteristics of XSS vulnerabilities rather than explicit details in the CVE.
OpenCVE Enrichment