CVE-2026-104993
Description
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email (Contact Email custom field htmlvar_name)' parameter in all versions up to, and including, 2.8.188 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires that an administrator has added and configured the Contact Email custom field to render on the public single-listing output page, and that the administrator subsequently approves the attacker's submitted listing.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/AyeCode/geodirectory/archive/refs/heads/master.zip
- https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.188/includes/class-geodir-post-data.php#L949
- https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.188/includes/custom-fields/output-functions.php#L1448
- https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.188/includes/post-functions.php#L1845
- https://plugins.trac.wordpress.org/changeset/3728472/geodirectory/trunk/includes/custom-fields/output-functions.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1356ec70-4264-4687-8082-7d87a8978082?source=cve
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.