PatchSiren cyber security CVE debrief
CVE-2025-15677 GeoDirectory CVE debrief
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. This vulnerability affects WordPress sites using the GeoDirectory plugin, especially those with high-privilege users. Evidence is limited to public sources and may not cover all affected deployments. Defenders should verify affected scope and vendor guidance. AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T07:16:33.493Z and has not been modified since then. Reviewing compensating controls for exposed systems while remediation is scheduled and verified is crucial. Checking relevant monitoring, detection, and logs for exposed assets that need extra review can help prevent further exploitation.
- Vendor
- GeoDirectory
- Product
- GeoDirectory WordPress plugin
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-08-05
Who should care
Administrators of WordPress sites using the GeoDirectory plugin, especially those with high-privilege users such as editors and above, should prioritize reviewing and updating the plugin to version 2.8.110 or later. They should also ensure that high-privilege users do not have unfiltered_html capability and monitor for suspicious activity on the admin page. Vulnerability management and security teams should review the CVE record and vendor guidance to assess operational impact and plan mitigations. Compensating controls may be necessary for exposed systems while remediation is scheduled and verified. Asset inventory and monitoring can help identify potentially affected systems. Rollback/change windows may be required to apply updates without disrupting operations. Source tracking can help verify the effectiveness of mitigations and updates. Security teams should also review relevant monitoring, detection, and logs for exposed assets that need extra review. Exceptions and retesting of remediated assets should be tracked, and the item should only be closed after evidence is documented. This may involve confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Reviewing compensating controls for exposed systems while remediation is scheduled and verified is crucial. Checking relevant monitoring, detection, and logs for exposed assets that need extra review can help prevent further exploitation. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented ensures thorough vulnerability management.
Technical summary
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. This vulnerability affects WordPress sites using the GeoDirectory plugin, especially those with high-privilege users.
Defensive priority
Administrators should prioritize reviewing and updating the GeoDirectory WordPress plugin to version 2.8.110 or later, and ensure that high-privilege users such as editors and above do not have unfiltered_html capability.
Recommended defensive actions
- Review and update the GeoDirectory WordPress plugin to version 2.8.110 or later
- Ensure high-privilege users do not have unfiltered_html capability
- Monitor for suspicious activity on the admin page
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Evidence is limited to public sources and may not cover all affected deployments. Defenders should verify affected scope and vendor guidance.
Official resources
-
CVE-2025-15677 CVE record
CVE.org
-
CVE-2025-15677 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T07:16:33.493Z and has not been modified since then.