PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-93897 paoltaia CVE debrief

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field in all versions up to, and including, 2.8.181. Authenticated attackers with subscriber-level access can inject web scripts that execute when a user accesses an injected page. This vulnerability allows attackers to inject malicious scripts via text-type custom fields, such as phone fields, using entity-encoded angle brackets to bypass security checks. Defenders should verify plugin versions and update to prevent exploitation.

Vendor
paoltaia
Product
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
CVSS
MEDIUM 6.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for WordPress installations with the GeoDirectory plugin should assess exposure and prioritize updates to prevent exploitation. This includes reviewing the plugin version, restricting access to sensitive pages and features, and monitoring for suspicious activity and injected scripts. Additionally, defenders should consider compensating controls for exposed systems while remediation is scheduled and verified.

Why it matters

CVE-2026-93897 allows authenticated attackers to inject web scripts via text-type custom fields in the GeoDirectory plugin. Defenders should verify and update the plugin, restrict access, and monitor for suspicious activity.

  • Attackers can inject malicious scripts that execute on page access.
  • Subscriber-level access is sufficient for exploitation.
  • Verify plugin version and update to prevent exploitation.
  • Monitor for suspicious activity and injected scripts.

Technical summary

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field in all versions up to, and including, 2.8.181. This is due to insufficient input sanitization and output escaping. An attacker can inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload must be stored in a text-type custom field via the AJAX geodir_save_post endpoint, using entity-encoded angle brackets to bypass security checks.

Defensive priority

Defenders should prioritize verifying and updating the GeoDirectory plugin to prevent exploitation.

Recommended defensive actions

  • Verify and update the GeoDirectory plugin to the latest version.
  • Restrict access to sensitive pages and features.
  • Monitor for suspicious activity and injected scripts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability allows authenticated attackers with subscriber-level access to inject arbitrary web scripts via text-type custom fields, such as phone fields, using entity-encoded angle brackets to bypass security checks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-93897 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-93897

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-93897 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93897

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.