Description
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Contributor Cross Site Scripting (XSS) is disclosed for GeoDirectory plugin versions 2.8.172 and earlier. The CVE description does not detail the exact mechanism, but XSS typically means that a malicious script can be injected and executed in the browsers of users who view content processed by the plugin. The flaw is classified as CWE‑79, indicating that data submitted or displayed by the plugin may not be properly validated or escaped before rendering. Based on the nature of the flaw, it is inferred that the injection of JavaScript could affect visitors of the site.

Affected Systems

WordPress sites that have installed the GeoDirectory plugin up to version 2.8.172 are affected. The vendor is Paolo. Any WordPress installation using this plugin and its legacy versions is at risk until the plugin is upgraded.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS data is unavailable and the vulnerability is not included in the CISA KEV catalog. Based on the CVE title and common behavior of XSS flaws, a likely attack vector involves unsanitized input or output when a user submits or views content via the plugin. The impact is confined to the victim’s browser session and does not elevate privileges or compromise the server itself. These inferences are drawn from the typical characteristics of XSS vulnerabilities rather than explicit details in the CVE.

Generated by OpenCVE AI on August 18, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GeoDirectory plugin to the latest supported release, which removes the XSS flaw.
  • Ensure that any data rendered by the plugin is properly sanitized or escaped, addressing the underlying CWE‑79 weakness.
  • Deploy a web application firewall or a WordPress security plugin configured to detect and block XSS payloads to provide an additional layer of defence.

Generated by OpenCVE AI on August 18, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Paolo
Paolo geodirectory
Wordpress
Wordpress wordpress
Vendors & Products Paolo
Paolo geodirectory
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
Title WordPress GeoDirectory plugin <= 2.8.172 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Paolo Geodirectory
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:28:10.031Z

Reserved: 2026-07-31T06:24:41.650Z

Link: CVE-2026-68565

cve-icon Vulnrichment

Updated: 2026-08-18T14:28:07.125Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:00.380

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-68565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T17:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')