PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15677 GeoDirectory CVE debrief

The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. This vulnerability affects WordPress sites using the GeoDirectory plugin, especially those with high-privilege users. Evidence is limited to public sources and may not cover all affected deployments. Defenders should verify affected scope and vendor guidance. AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T07:16:33.493Z and has not been modified since then. Reviewing compensating controls for exposed systems while remediation is scheduled and verified is crucial. Checking relevant monitoring, detection, and logs for exposed assets that need extra review can help prevent further exploitation.

Vendor
GeoDirectory
Product
GeoDirectory WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-05
Advisory published
2026-08-05
Advisory updated
2026-08-05

Who should care

Administrators of WordPress sites using the GeoDirectory plugin, especially those with high-privilege users such as editors and above, should prioritize reviewing and updating the plugin to version 2.8.110 or later. They should also ensure that high-privilege users do not have unfiltered_html capability and monitor for suspicious activity on the admin page. Vulnerability management and security teams should review the CVE record and vendor guidance to assess operational impact and plan mitigations. Compensating controls may be necessary for exposed systems while remediation is scheduled and verified. Asset inventory and monitoring can help identify potentially affected systems. Rollback/change windows may be required to apply updates without disrupting operations. Source tracking can help verify the effectiveness of mitigations and updates. Security teams should also review relevant monitoring, detection, and logs for exposed assets that need extra review. Exceptions and retesting of remediated assets should be tracked, and the item should only be closed after evidence is documented. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Reviewing compensating controls for exposed systems while remediation is scheduled and verified is crucial. Checking relevant monitoring, detection, and logs for exposed assets that need extra review can help prevent further exploitation. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented ensures thorough vulnerability management.

Technical summary

The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. This vulnerability affects WordPress sites using the GeoDirectory plugin, especially those with high-privilege users.

Defensive priority

Administrators should prioritize reviewing and updating the GeoDirectory WordPress plugin to version 2.8.110 or later, and ensure that high-privilege users such as editors and above do not have unfiltered_html capability.

Recommended defensive actions

  • Review and update the GeoDirectory WordPress plugin to version 2.8.110 or later
  • Ensure high-privilege users do not have unfiltered_html capability
  • Monitor for suspicious activity on the admin page
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Evidence is limited to public sources and may not cover all affected deployments. Defenders should verify affected scope and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T07:16:33.493Z and has not been modified since then.