CVE-2025-15677
GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
| Vendor | unknown |
| Product | geodirectory |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown geodirectory
Be the first to know when new unknown vulnerabilities affecting unknown geodirectory are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / GeoDirectory
0 < 2.8.110
References
Credits
Krugov Artyom WPScan