WordPress security by component
GeoDirectory
Plugin description
GeoDirectory is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2026; the highest CVE/CNA score is 9.3.
Plugin slug:
geodirectoryLatest vulnerability
CVE-2026-57681: GeoDirectory: Server-side request forgery
GeoDirectory is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.8.161.
| Safe version |
|
||
|---|---|---|---|
| Jul 02, 2026 |
CVE-2026-57681
GeoDirectory: Server-side request forgery
GeoDirectory is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.8.161.
|
2.8.162 |
CVE6.4
NVDPending
|
| Jun 26, 2026 |
CVE-2026-54831
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.162.
|
2.8.163 |
CVE9.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39512
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.152.
|
2.8.154 |
CVE9.3
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42671
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.157.
|
2.8.158 |
CVE6.5
NVDPending
|
| Jan 23, 2026 |
CVE-2026-24549
GeoDirectory: Cross-site request forgery
GeoDirectory is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 12, 2025 |
CVE-2025-12833
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: A security weakness
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 26, 2025 |
CVE-2024-13507
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: SQL injection
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jul 11, 2025 |
CVE-2025-6200
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Feb 11, 2025 |
CVE-2024-13506
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: Cross-site scripting
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 02, 2025 |
CVE-2024-56259
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 01, 2024 |
CVE-2024-43981
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Oct 28, 2024 |
CVE-2024-50437
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Aug 18, 2024 |
CVE-2024-43145
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Apr 23, 2024 |
CVE-2024-3732
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: Cross-site scripting
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 28, 2023 |
CVE-2023-50845
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: SQL injection
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Feb 27, 2023 |
CVE-2023-0278
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Jan 23, 2023 |
CVE-2022-4775
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Oct 11, 2021 |
CVE-2021-24720
GeoDirectory Business Directory: Cross-site scripting
GeoDirectory Business Directory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|