Vulnerability in HivePress – Business Directory, Listings & Classified Ads Plugin — CVE-2026-103520
What to do now
Update HivePress – Business Directory, Listings & Classified Ads Plugin to 1.7.32 or later.
Affected versions
- Everything up to and including 1.7.31
Affected: HivePress – Business Directory, Listings & Classified Ads Plugin (plugin, hivepress)
What the vulnerability is
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom text attribute (user-defined field name)' parameter in all versions up to, and including, 1.7.31 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when an administrator has configured a Text attribute whose display format places the %value% token inside an HTML attribute (e.g., title="%value%"), which is a documented HivePress pattern.