Impact
The GeoDirectory plugin is vulnerable because the 'business_hours' parameter is not properly sanitized or escaped before being stored. The flaw allows a subscriber‑level or higher authenticated user, who owns a listing, to enter malicious scripts that will be rendered on any page that displays the listing. The primary result is client‑side code execution, allowing attackers to perform phishing, cookie theft, or other malicious actions against users who view the affected pages.
Affected Systems
WordPress sites running the GeoDirectory – WP Business Directory Plugin (and Classified Listings Directory) version 2.8.183 or earlier are impacted. Any user with Subscriber or higher privileges who owns a listing can trigger the flaw.
Risk and Exploitability
CVSS score is 6.4, indicating medium severity. No EPSS score is provided and the vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access and a valid post‑author nonce, with the likely vector being the plugin’s AJAX endpoint when a subscriber edits their listing. When these conditions are met, the injected script will run in the browser context of any visitor to the listing page.
OpenCVE Enrichment