← WordPress Vulnerabilities
WordPress security by component

GeoDirectory

GeoDirectory is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: geodirectory

CVE-2026-57681: GeoDirectory: Server-side request forgery

GeoDirectory is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.8.161.

PublishedJul 02, 2026
Known safe version2.8.162
Safe version
Jul 02, 2026 CVE-2026-57681
GeoDirectory: Server-side request forgery
GeoDirectory is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.8.161.
2.8.162
CVE6.4
NVDPending
Jun 26, 2026 CVE-2026-54831
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.162.
2.8.163
CVE9.3
NVDPending
Jun 15, 2026 CVE-2026-39512
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.152.
2.8.154
CVE9.3
NVDPending
Jun 01, 2026 CVE-2026-42671
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.157.
2.8.158
CVE6.5
NVDPending
Jan 23, 2026 CVE-2026-24549
GeoDirectory: Cross-site request forgery
GeoDirectory is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Nov 12, 2025 CVE-2025-12833
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: A security weakness
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by a security weakness. Exploitation requires at least author-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Jul 26, 2025 CVE-2024-13507
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: SQL injection
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending
Jul 11, 2025 CVE-2025-6200
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVDPending
Feb 11, 2025 CVE-2024-13506
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: Cross-site scripting
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Jan 02, 2025 CVE-2024-56259
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Nov 01, 2024 CVE-2024-43981
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Oct 28, 2024 CVE-2024-50437
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVD5.4
Aug 18, 2024 CVE-2024-43145
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD8.8
Apr 23, 2024 CVE-2024-3732
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: Cross-site scripting
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Dec 28, 2023 CVE-2023-50845
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: SQL injection
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Feb 27, 2023 CVE-2023-0278
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Jan 23, 2023 CVE-2022-4775
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Oct 11, 2021 CVE-2021-24720
GeoDirectory Business Directory: Cross-site scripting
GeoDirectory Business Directory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4