All 2 CVE vulnerabilities found in HivePress – Business Directory, Listings & Classified Ads Plugin, with AI-generated Chinese analysis, references, and POCs.
Vendor: hivepress
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-107657 | HivePress <= 1.7.31 - Unauthenticated Stored Cross-Site Scripting via Custom User Attribute Value via Registration Form CWE-79 | 7.2 | High | 2026-10-10 |
| CVE-2026-103520 | HivePress <= 1.7.31 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Listing Attribute Value in Administrator-configured HTML Format CWE-79 | 6.4 | Medium | 2026-10-10 |
All 2 known CVE vulnerabilities affecting HivePress – Business Directory, Listings & Classified Ads Plugin with full Chinese analysis, references, and POCs where available.