๐Ÿ” CVE Alert

CVE-2026-14307

UNKNOWN 0.0

Geotargeting WP < 3.5.6.2 - Reflected XSS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into submitting a crafted request.

Vendor unknown
Product geotargetingwp
Published Aug 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown geotargetingwp

Be the first to know when new unknown vulnerabilities affecting unknown geotargetingwp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / geotargetingwp
0 < 3.5.6.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/5f55b592-9113-47d1-8b48-6ba785c0834a/

Credits

andrew gomez WPScan