CVE-2025-8295
Published
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
<p><strong>Employee Directory</strong> is a flexible staff and team directory plugin that works out of the box for small teams and supports enterprise use cases such as intranets and centralized identity integration via official add-ons and the Professional version.</p>
<p>Create a professional, searchable employee directory for your WordPress site. Display employees, faculty, or team members in a clean, filterable layout with photos, job titles, departments, locations, and custom fields. Visitors can browse or search by name, title, or department to quickly find the right person.</p>
<p>Employee Directory supports a modular architecture designed for growing organizations. Start with a simple directory and extend it as your needs evolve.</p>
<h3>Advanced Features & Integrations</h3>
<p>Employee Directory supports advanced organizational and intranet use cases through official add-ons and the Professional version.</p>
<p><strong>Available capabilities include:</strong></p>
<ul>
<li>Organizational hierarchies and org charts</li>
<li><strong>LDAP / Active Directory</strong> integration</li>
<li><strong>Microsoft Entra ID (Azure AD)</strong> integration</li>
<li>Bulk employee data synchronization</li>
<li>Workflow automation (optional, customizable feature)</li>
</ul>
<h3>Licensing</h3>
<p>The Professional version and add-ons are licensed separately based on usage and include access to support.</p>
<blockquote>
<p><strong>LIVE DEMO SITE</strong><br />
<a href="https://employee-directory-com.emdplugins.com?pk_campaign=employee-directory-com&pk_kwd=readme" rel="nofollow ugc">Employee Directory Starter Demo Site</a><br />
<a href="https://employee-directory.emdplugins.com/?pk_campaign=employee-directory-com&pk_kwd=readme" rel="nofollow ugc">Employee Directory Professional Demo Site</a><br />
Powerful | Easy to use | Beautiful</p>
</blockquote>
<h3>Getting Started</h3>
<p>Watch our introduction video to quickly get started with Employee Directory.</p>
<p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/z_vhhJz_uEc?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p>
<p><strong>Employee Directory YouTube Playlist</strong></p>
<p>A collection of videos explaining Employee Directory concepts, features, and setup:</p>
<p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/-woxENYS8eY?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent&listType=playlist&list=PLxQpKElaVx8uROIRtpaATJTYr3HdPNybM" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p>
<p><strong>RELATED PLUGINS YOU MAY LIKE</strong></p>
<ul>
<li><a href="https://kcentercom.emdplugins.com/" rel="nofollow ugc">Knowledge Center Starter</a> — Knowledge base software for helping customers and employees find answers.</li>
<li><a href="https://espotlight-com.emdplugins.com/" rel="nofollow ugc">Employee Spotlight Starter</a> — Display and manage staff profiles.</li>
<li><a href="https://simcom.emdplugins.com/" rel="nofollow ugc">Software Issue Manager Starter</a> — Issue and project management solution.</li>
<li><a href="https://requestaquote.emdplugins.com/" rel="nofollow ugc">Request a Quote Starter</a> — Sales quoting solution for WordPress.</li>
<li><a href="https://wpticketcom.emdplugins.com/" rel="nofollow ugc">WP Ticket Starter</a> — Customer support and helpdesk ticketing.</li>
<li><a href="https://wpeasycontactcom.emdplugins.com/" rel="nofollow ugc">WP Easy Contact Starter</a> — Contact management solution for WordPress.</li>
</ul>
<h3>Credits</h3>
<p>This plugin was generated using <a href="https://wpappstudio.com/" rel="nofollow ugc">WP App Studio</a>.</p>