CVE-2026-96766
Last modified
CVE-2026-96766 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Description
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the AJAX save handler validates only post authorship and a nonce with no additional capability check, allowing any subscriber-level user who owns a listing to exploit this vulnerability.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | <= 2.8.183 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-96766?
How severe is CVE-2026-96766?
How do I fix CVE-2026-96766?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-96758orval @orval/core before 8.28.0 contains a code injection vu…9.8
- CVE-2026-96759orval before 8.29.0 fails to escape the operationId paramete…9.8
- CVE-2026-9676The F4 Post Tree WordPress plugin before 2.0.5 does not perf…4.3
- CVE-2026-96762A vulnerability was determined in kvcache-ai mooncake up to …7.3
- CVE-2026-96763A security flaw has been discovered in kvcache-ai mooncake u…5.4
- CVE-2026-96764A weakness has been identified in kvcache-ai mooncake up to …4.3
- CVE-2026-9677The Shariff for WordPress Shariff for WordPress plugin throu…4.8
- CVE-2026-96770All published s2s-proxy versions through 0.2.2 are affected.…9.3
- CVE-2026-96772A security flaw has been discovered in Intelliants Subrion C…5.3
- CVE-2026-96773A weakness has been identified in Intelliants Subrion CMS up…4.3
- CVE-2026-96774A vulnerability was found in SPON Communications IP Network …5.3
- CVE-2026-96775MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_A…8.8
Are you affected by CVE-2026-96766?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
