{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/listdom-ai-powered-business-directory-with-classifieds-ads-listings--5.8.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:listdom:listdom:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-19796"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Listdom: AI-powered Business Directory with Classifieds Ads Listings (\u003c= 5.8.1)"],"_cs_severities":["high"],"_cs_tags":["xss","wordpress","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-19796. The vulnerability stems from insufficient sanitization and escaping of user-supplied input within the 'lsd[displ][style]' parameter.\u003c/p\u003e\n\u003cp\u003eThe issue affects all plugin versions up to and including 5.8.1. Successful exploitation allows an unauthenticated attacker to inject malicious JavaScript into web pages rendered by the plugin. This script executes within the context of the browser session of any user who accesses the compromised page, potentially leading to session hijacking, unauthorized actions, or further client-side exploitation. This vulnerability requires non-default configurations to be present, specifically the activation of the Listdom Pro add-on and the enabling of the 'Display Options Per Listing' setting.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the execution of arbitrary JavaScript in the victim's browser session. This can lead to account takeover, unauthorized modification of content, or data theft. The vulnerability affects websites utilizing the Listdom plugin with specific premium add-ons enabled, creating a significant risk for directories and classified sites running these components.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin to the latest version beyond 5.8.1 to incorporate input sanitization patches for CVE-2026-19796.\u003c/li\u003e\n\u003cli\u003eIf an immediate update is not possible, disable the Listdom Pro add-on or the 'Display Options Per Listing' functionality to mitigate the exploit path.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to detect and block malicious script injection attempts in POST requests targeting the plugin's configuration parameters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-01T07:03:36Z","date_published":"2026-09-01T07:03:36Z","id":"https://feed.craftedsignal.io/briefs/2026-09-listdom-xss/","summary":"An unauthenticated stored XSS vulnerability in the Listdom WordPress plugin allows attackers to inject arbitrary scripts when specific premium add-ons are enabled.","title":"Stored XSS Vulnerability in Listdom WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-listdom-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Listdom: AI-Powered Business Directory With Classifieds Ads Listings (\u003c= 5.8.1)","version":"https://jsonfeed.org/version/1.1"}