Junglewise Threat Intelligence

CVE-2026-19796: Listdom AI-powered Business Directory Stored Cross-Site Scripting

CVE-2026-19796 · Severity: high · CVSS 7.2 · Published 2026-09-01

Executive brief

Listdom is a WordPress plugin that provides a business directory and classifieds listing platform. The plugin is vulnerable to stored cross-site scripting (XSS), allowing unauthenticated attackers to inject malicious scripts that execute whenever users view affected pages. This attack requires non-default configurations (Listdom Pro add-on and specific display settings) to be enabled, but could enable account hijacking, session theft, or malware distribution to site visitors.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the 'lsd[displ][style]' parameter, caused by insufficient input sanitization and output escaping in the Listdom plugin (versions up to 5.8.1). An unauthenticated attacker can inject arbitrary JavaScript that persists in the database and executes in the browsers of all users who view the affected listing page. Exploitation requires the Listdom Pro add-on to be active and the 'Display Options Per Listing' feature to be enabled—both non-default configurations. The injected scripts execute with the privileges of the affected user, potentially allowing credential theft, session hijacking, or site defacement. A patch addressing the input sanitization and output escaping is recommended.

Affected products

  • Tina4 Listdom: AI-powered Business Directory with Classifieds Ads Listings up to and including 5.8.1

Timeline

  • 2026-09-01: disclosed

References