rootpwn

medium · CVSS v3 6.4 · EPSS 0.00201

CVE-2026-96647

The Listdom WordPress plugin (up to 6.1.1) has a stored XSS flaw that allows authenticated users with contributor-level or higher to inject

Overview

The Listdom WordPress plugin (up to 6.1.1) has a stored XSS flaw that allows authenticated users with contributor-level or higher to inject malicious scripts via the 'lsd[remark]' field. The vulnerability can also be abused by subscriber-level users due to a missing capability check and a publicly exposed nonce. This flaw enables attackers to execute arbitrary JavaScript in the context of any user who views the compromised listing page.

Description

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up to, and including, 6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users because the listing-creation branch of the AJAX handler omits a capability check, and the required nonce is publicly emitted on any page containing the [listdom-dashboard] shortcode.

Impact

Confidentiality: attackers can steal session cookies or other sensitive data from users who view the injected page. Integrity: malicious scripts can modify page content or redirect users. Availability: repeated XSS can degrade user experience. The primary impact is on site administrators, contributors, and any visitors who view compromised listings.

Remediation

1. Update the Listdom plugin to the latest version (>=6.2) where the input sanitization and capability checks are fixed. 2. If an update is not immediately possible, disable the plugin or remove the [listdom-dashboard] shortcode from public pages. 3. Restrict contributor and subscriber roles from accessing the listing creation AJAX endpoint by applying a role‑based capability check or using a WAF rule to block the 'lsd[remark]' parameter. 4. Implement a site‑wide XSS filter (e.g., ModSecurity rule) to escape or block suspicious script payloads.

Risk context

The CVE has a medium severity score (CVSS 6.4) and a very low EPSS (0.00201), indicating that while the flaw is not highly likely to be exploited, it remains a valid threat that should be mitigated promptly to prevent potential XSS attacks.

Affected products

  • WordPress
  • Listdom AI-powered Business Directory
  • Listdom Classifieds Ads Listings

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
—
EPSS
0.00201

wordpress plugin xss stored authentication listdom medium ephemeral

← All CVEs