---
id: CVE-2026-96766
title: >-
  The GeoDirectory – WP Business Directory Plugin and Classified Listings
  Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting
  via the 'business_hours' parameter in all versions up to, and including,
  2.8.183 due to i…
summary: >-
  The GeoDirectory – WP Business Directory Plugin and Classified Listings
  Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting
  via the 'business_hours' parameter in all versions up to, and including,
  2.8.183 due to i…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: paoltaia
product: GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
affected:
  - >-
    geodirectory_wp_business_directory_plugin_and_classified_listings_directory
    <= 2.8.183
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:08:08.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96766'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.182/includes/business-hours-functions.php#L965
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.182/includes/class-geodir-ajax.php#L821
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.182/includes/class-geodir-post-data.php#L1661
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.182/includes/custom-fields/input-functions-aui.php#L2278
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3710682%40geodirectory&new=3710682%40geodirectory
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/bc743651-cfbc-487b-9d1b-9aab6d3a57b7?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T10:37:49.691722Z'
ingestedAt: '2026-09-25T07:01:12.112Z'
---

## Overview

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the AJAX save handler validates only post authorship and a nonce with no additional capability check, allowing any subscriber-level user who owns a listing to exploit this vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
