<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Listdom: AI-Powered Business Directory With Classifieds Ads Listings (&lt;= 5.8.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/listdom-ai-powered-business-directory-with-classifieds-ads-listings--5.8.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 07:03:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/listdom-ai-powered-business-directory-with-classifieds-ads-listings--5.8.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS Vulnerability in Listdom WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-listdom-xss/</link><pubDate>Tue, 01 Sep 2026 07:03:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-listdom-xss/</guid><description>An unauthenticated stored XSS vulnerability in the Listdom WordPress plugin allows attackers to inject arbitrary scripts when specific premium add-ons are enabled.</description><content:encoded><![CDATA[<p>The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-19796. The vulnerability stems from insufficient sanitization and escaping of user-supplied input within the 'lsd[displ][style]' parameter.</p>
<p>The issue affects all plugin versions up to and including 5.8.1. Successful exploitation allows an unauthenticated attacker to inject malicious JavaScript into web pages rendered by the plugin. This script executes within the context of the browser session of any user who accesses the compromised page, potentially leading to session hijacking, unauthorized actions, or further client-side exploitation. This vulnerability requires non-default configurations to be present, specifically the activation of the Listdom Pro add-on and the enabling of the 'Display Options Per Listing' setting.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the execution of arbitrary JavaScript in the victim's browser session. This can lead to account takeover, unauthorized modification of content, or data theft. The vulnerability affects websites utilizing the Listdom plugin with specific premium add-ons enabled, creating a significant risk for directories and classified sites running these components.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Update the Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin to the latest version beyond 5.8.1 to incorporate input sanitization patches for CVE-2026-19796.</li>
<li>If an immediate update is not possible, disable the Listdom Pro add-on or the 'Display Options Per Listing' functionality to mitigate the exploit path.</li>
<li>Deploy web application firewall (WAF) rules to detect and block malicious script injection attempts in POST requests targeting the plugin's configuration parameters.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>xss</category><category>wordpress</category><category>web-vulnerability</category></item></channel></rss>