CVE-2025-15677 – GeoDirectory < 2.8.110 – Editor+ Stored XSS – POC

CVE-2025-15677 – GeoDirectory < 2.8.110 – Editor+ Stored XSS – POC

WordPress plugins that provide business directory functionality often allow administrators and editors to customize categories, icons, images, and other visual elements. While these features improve usability, they also increase the attack surface if user-controlled input is not properly validated before being stored and rendered.

During security testing of the GeoDirectory plugin, a Stored Cross-Site Scripting (Stored XSS) vulnerability was discovered affecting versions prior to 2.8.110. The vulnerability allows an authenticated Editor (or higher) to inject malicious JavaScript into the Map Icon parameter of a Place Category. The payload is permanently stored and later executed whenever the vulnerable page is viewed by another privileged user.

Because the malicious payload is stored inside the WordPress database, every administrator who accesses the affected interface can unknowingly execute attacker-controlled JavaScript, potentially resulting in complete administrative account compromise.

CVE-2025-15675 – Charitable < 1.8.5.3 – Admin+ Stored XSS – POC

CVE-2025-15675 – Charitable < 1.8.5.3 – Admin+ Stored XSS – POC

Charitable is a widely used WordPress donation and fundraising plugin that enables organizations to create fundraising campaigns, donation forms, recurring payment options, and crowdfunding initiatives. With its drag-and-drop campaign builder and customizable templates, it is trusted by thousands of nonprofits and charities to manage online donations.

During security testing, a Stored Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 1.8.5.3. The vulnerability exists in the campaign builder, where the ALT Text field for campaign images fails to properly sanitize user input before storing and rendering it. As a result, an authenticated administrator can inject malicious JavaScript that is permanently stored and executed whenever the vulnerable content is rendered.

CVE-2025-13354 – TaxoPress – Missing Authorization – POC

CVE-2025-13354 – TaxoPress – Missing Authorization – POC

CVE-2025-13354 affects TaxoPress and allows authenticated Subscriber+ users to merge or delete arbitrary taxonomy terms through the taxopress_merge_terms_batch AJAX action. The handler validates a nonce that is available from profile.php but does not verify the taxonomy manage_terms capability. Its unbounded post lookup can also add significant load while terms are reassigned or removed.

CVE-2026-1673 – BEAR Bulk Editor – CSRF Term Deletion – POC

CVE-2026-1673 – BEAR Bulk Editor – CSRF Term Deletion – POC

CVE-2026-1673 affects BEAR Bulk Editor and Products Manager Professional for WooCommerce and is a cross site request forgery vulnerability that can delete WooCommerce taxonomy terms in versions through 1.1.5. The woobe_delete_tax_term AJAX action accepts tax_key and term_id without validating a WordPress nonce. An unauthenticated attacker can prepare a forged request that deletes product categories, tags, or other terms when a logged in administrator or shop manager visits a malicious page.

CVE-2026-1672 – BEAR Bulk Editor – CSRF to Product Update – POC

CVE-2026-1672 – BEAR Bulk Editor – CSRF to Product Update – POC

CVE-2026-1672 affects BEAR Bulk Editor and Products Manager Professional for WooCommerce and is a cross site request forgery vulnerability that can modify WooCommerce product data in versions through 1.1.5. The woobe_redraw_table_row AJAX action accepts product_id, field, and value without validating a WordPress nonce. An unauthenticated attacker can prepare a forged request that changes prices, descriptions, or other product fields when a logged in administrator or shop manager visits a malicious page.

CVE-2026-0738 – Shortcodes Ultimate – Stored XSS – POC

CVE-2026-0738 – Shortcodes Ultimate – Stored XSS – POC

CVE-2026-0738 affects Shortcodes Ultimate and is an authenticated Author+ stored cross site scripting vulnerability in the su_carousel shortcode. In versions through 7.4.8, an unsafe value in the su_slide_link attachment field can be stored and rendered in carousel output. When a visitor moves the pointer over the affected slide link, browser code can run in that visitor’s session.