CVE-2026-14307EPSS p5.0%

CVE-2026-14307CVE-2026-14307

Description

The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victim is tricked into submitting a crafted request.

Scoring

CVSS 7.1 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS0.16% probability of exploitation · percentile 5.0% · 2026-10-05T12:00:23Z
Last modified2026-08-31
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.