PatchSiren

webilia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM webilia CVE published 2026-10-02

CVE-2026-96647

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lsd[remark]' parameter in all versions up to, and including, 6.1.1. This is possible due to insufficient input sanitization and output escaping. Authenticated attackers with contributor-level access and above can inject arbitrary web scripts in pages that will [truncated]