CVE-2025-6200: GeoDirectory < 2.8.120 - Contributor+ Stored XSS
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6200?
CVE-2025-6200 has a medium severity rating due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-6200?
To fix CVE-2025-6200, upgrade the GeoDirectory WordPress plugin to version 2.8.120 or later.
Who is affected by CVE-2025-6200?
Users with contributor roles and above in sites using GeoDirectory versions before 2.8.120 are affected by CVE-2025-6200.
What is the impact of CVE-2025-6200?
The impact of CVE-2025-6200 is that it allows authenticated users to inject harmful scripts into posts or pages.
Is there a workaround for CVE-2025-6200?
Currently, there are no specific workarounds for CVE-2025-6200 other than updating to the latest version of the plugin.