CVE-2026-14307
Received Received - Intake

Stored Cross-Site Scripting in GeotargetingWP WordPress Plugin

Vulnerability report for CVE-2026-14307, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-30

Last updated on: 2026-08-30

Assigner: WPScan

Description

The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into submitting a crafted request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-30
Last Modified
2026-08-30
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
geotargetingwp geotargeting_wp to 3.5.6.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a reflected Cross-Site Scripting (XSS) flaw in the geotargetingwp WordPress plugin before version 3.5.6.2. It occurs because the plugin does not properly sanitize or escape certain parameters before reflecting them back in AJAX responses with an HTML content type. Unauthenticated attackers can exploit this to inject malicious scripts that execute when a victim submits a specially crafted request.

Detection Guidance

Check if the geotargetingwp WordPress plugin version is below 3.5.6.2. Use WordPress admin panel or run commands like 'wp plugin list' in WP-CLI to verify the installed version.

Impact Analysis

This vulnerability allows attackers to inject malicious scripts into web pages served by the vulnerable plugin. If you visit a page with the injected script, it could steal your cookies, session tokens, or other sensitive data. It could also redirect you to malicious sites or perform actions on your behalf without your consent.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, which may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations using the vulnerable plugin may face compliance violations, legal penalties, or reputational damage if user data is compromised.

Mitigation Strategies

Update the geotargetingwp plugin to version 3.5.6.2 or later immediately. If updating is not possible, consider disabling the plugin temporarily until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14307. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart