PatchSiren

paoltaia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM paoltaia CVE published 2026-09-25

CVE-2026-96766

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183. This vulnerability allows authenticated attackers with subscriber-level access to inject arbitrary web scripts, which execute when a user accesses an injected page. The AJAX save [truncated]

MEDIUM paoltaia CVE published 2026-09-25

CVE-2026-93897

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field in all versions up to, and including, 2.8.181. Authenticated attackers with subscriber-level access can inject web scripts that execute when a user accesses an injected page. This vulnerability allows attackers to inject malicious sc [truncated]