CVE-2025-15677: GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
Published Aug 5, 2026
·Updated
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in a multisite setup).
Affected Software
1 affected component
GeoDirectory WordPress plugin<2.8.110
Event History
Aug 5, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2025-15677?
The severity of CVE-2025-15677 is rated at 35.
2
How do I fix CVE-2025-15677?
To fix CVE-2025-15677, update the GeoDirectory WordPress plugin to version 2.8.110 or later.
3
Who is affected by CVE-2025-15677?
CVE-2025-15677 affects high-privilege users such as editors and above within the GeoDirectory WordPress plugin.
4
What type of vulnerability is CVE-2025-15677?
CVE-2025-15677 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
What version of GeoDirectory is vulnerable to CVE-2025-15677?
GeoDirectory versions prior to 2.8.110 are vulnerable to CVE-2025-15677.