CVE-2025-15677
Received Received - Intake

Stored Cross-Site Scripting in GeoDirectory WordPress Plugin

Vulnerability report for CVE-2025-15677, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: WPScan

Description

The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
geodirectory geodirectory to 2.8.110 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Stored Cross-Site Scripting (XSS) vulnerability in the GeoDirectory WordPress plugin before version 2.8.110. It occurs because the plugin does not properly sanitize and escape user input in the place-category setting before displaying it in an admin page. This allows high-privilege users like editors to inject malicious scripts even if the unfiltered_html capability is restricted.

Detection Guidance

Check if your GeoDirectory plugin version is below 2.8.110. Log in as an editor or admin and inspect the Place Categories settings page for unsanitized input. Look for unexpected scripts in the page source or admin interface.

Impact Analysis

Attackers with editor or higher privileges could inject malicious scripts into admin pages. These scripts could steal sensitive data, hijack sessions, or perform actions on behalf of the user. The impact depends on the privileges of the compromised account.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's data protection requirements or HIPAA's security rules. Organizations may face compliance penalties if user data is compromised due to this flaw.

Mitigation Strategies

Update the GeoDirectory plugin to version 2.8.110 or later immediately. If updating is not possible, restrict high-privilege user access to the Place Categories settings until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15677. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart