SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14307

HIGH · CVSS 7.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The geotargetingwp WordPress plugin prior to version 3.5.6.2 is vulnerable due to improper sanitization and escaping of parameters in AJAX responses, which can lead to cross-site scripting (XSS) attacks. This flaw allows unauthenticated attackers to inject malicious scripts that execute in the context of a victim's browser when they interact with a crafted request. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation risks.

CVE
CVE-2026-14307
Severity
HIGH
CVSS
7.1
EPSS
0.16%
WordPress

Original NVD Description

The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into submitting a crafted request.