What is CVE-2025-15677?
The GeoDirectory WordPress plugin before version 2.8.110 does not sanitize and escape the "place-cat" parameter, leading to Stored Cross-Site Scripting vulnerabilities in the admin page. High-privilege users like editors and above can inject malicious scripts even when the unfiltered_html capability is disabled. Updating to the latest plugin version is recommended.
Azərbaycanca: GeoDirectory WordPress plaginində 2.8.110 versiyasından əvvəl "place-cat" parametri sanitizə olunmur, bu da admin səhifəsində Stored Cross-Site Scripting hücumuna səbəb olur. Yüksək səlahiyyətli istifadəçilər (redaktor və yuxarı) `unfiltered_html` icazəsi söndürüldükdə belə zərərli skript yerləşdirə bilər. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What privilege level does an attacker need to exploit the CVE-2025-15677 vulnerability in the GeoDirectory plugin?
An attacker must have editor-level or higher privileges to carry out the Stored XSS attack.
Is it possible to exploit this vulnerability even when the `unfiltered_html` capability is disabled in WordPress?
Yes, this vulnerability allows high-privileged users to inject malicious scripts even when the `unfiltered_html` capability is disabled.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.