The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183. This vulnerability allows authenticated attackers with subscriber-level access to inject arbitrary web scripts, which execute when a user accesses an injected page. The AJAX save [truncated]
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field in all versions up to, and including, 2.8.181. Authenticated attackers with subscriber-level access can inject web scripts that execute when a user accesses an injected page. This vulnerability allows attackers to inject malicious sc [truncated]