MEDIUM
webilia
CVE published 2026-10-02
CVE-2026-96647
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lsd[remark]' parameter in all versions up to, and including, 6.1.1. This is possible due to insufficient input sanitization and output escaping. Authenticated attackers with contributor-level access and above can inject arbitrary web scripts in pages that will [truncated]