CVE-2026-14307
Geotargeting WP < 3.5.6.2 - Reflected XSS
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into submitting a crafted request.
| Vendor | unknown |
| Product | geotargetingwp |
| Published | Aug 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown geotargetingwp
Be the first to know when new unknown vulnerabilities affecting unknown geotargetingwp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / geotargetingwp
0 < 3.5.6.2
References
Credits
andrew gomez WPScan