CVE-2025-8295

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Employee Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘noaccess_msg’ parameter in all versions up to, and including, 4.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p><strong>Employee Directory</strong> is a flexible staff and team directory plugin that works out of the box for small teams and supports enterprise use cases such as intranets and centralized identity integration via official add-ons and the Professional version.</p> <p>Create a professional, searchable employee directory for your WordPress site. Display employees, faculty, or team members in a clean, filterable layout with photos, job titles, departments, locations, and custom fields. Visitors can browse or search by name, title, or department to quickly find the right person.</p> <p>Employee Directory supports a modular architecture designed for growing organizations. Start with a simple directory and extend it as your needs evolve.</p> <h3>Advanced Features &amp; Integrations</h3> <p>Employee Directory supports advanced organizational and intranet use cases through official add-ons and the Professional version.</p> <p><strong>Available capabilities include:</strong></p> <ul> <li>Organizational hierarchies and org charts</li> <li><strong>LDAP / Active Directory</strong> integration</li> <li><strong>Microsoft Entra ID (Azure AD)</strong> integration</li> <li>Bulk employee data synchronization</li> <li>Workflow automation (optional, customizable feature)</li> </ul> <h3>Licensing</h3> <p>The Professional version and add-ons are licensed separately based on usage and include access to support.</p> <blockquote> <p><strong>LIVE DEMO SITE</strong><br /> <a href="https://employee-directory-com.emdplugins.com?pk_campaign=employee-directory-com&amp;pk_kwd=readme" rel="nofollow ugc">Employee Directory Starter Demo Site</a><br /> <a href="https://employee-directory.emdplugins.com/?pk_campaign=employee-directory-com&amp;pk_kwd=readme" rel="nofollow ugc">Employee Directory Professional Demo Site</a><br /> Powerful | Easy to use | Beautiful</p> </blockquote> <h3>Getting Started</h3> <p>Watch our introduction video to quickly get started with Employee Directory.</p> <p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/z_vhhJz_uEc?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p><strong>Employee Directory YouTube Playlist</strong></p> <p>A collection of videos explaining Employee Directory concepts, features, and setup:</p> <p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/-woxENYS8eY?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent&#038;listType=playlist&#038;list=PLxQpKElaVx8uROIRtpaATJTYr3HdPNybM" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <p><strong>RELATED PLUGINS YOU MAY LIKE</strong></p> <ul> <li><a href="https://kcentercom.emdplugins.com/" rel="nofollow ugc">Knowledge Center Starter</a> — Knowledge base software for helping customers and employees find answers.</li> <li><a href="https://espotlight-com.emdplugins.com/" rel="nofollow ugc">Employee Spotlight Starter</a> — Display and manage staff profiles.</li> <li><a href="https://simcom.emdplugins.com/" rel="nofollow ugc">Software Issue Manager Starter</a> — Issue and project management solution.</li> <li><a href="https://requestaquote.emdplugins.com/" rel="nofollow ugc">Request a Quote Starter</a> — Sales quoting solution for WordPress.</li> <li><a href="https://wpticketcom.emdplugins.com/" rel="nofollow ugc">WP Ticket Starter</a> — Customer support and helpdesk ticketing.</li> <li><a href="https://wpeasycontactcom.emdplugins.com/" rel="nofollow ugc">WP Easy Contact Starter</a> — Contact management solution for WordPress.</li> </ul> <h3>Credits</h3> <p>This plugin was generated using <a href="https://wpappstudio.com/" rel="nofollow ugc">WP App Studio</a>.</p>
WordPress Plugin DirectoryWordPress Plugin Directory
43.9K