WordPress · Geotargetingwp · CVE-2026-14307
**Name of the Vulnerable Software and Affected Versions**
geotargetingwp versions prior to 3.5.6.2
**Description**
The plugin fails to sanitize or escape several parameters before reflecting them in AJAX responses served with an HTML content type. This allows unauthenticated attackers to perform reflected Cross-Site Scripting (XSS), where arbitrary web scripts are executed when a victim is tricked into submitting a crafted request.
**Recommendations**
Update the plugin to version 3.5.6.2 or later.