GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory creates business directories and classified listings with locations, categories, search, filters, maps, and user submissions.
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (geodirectory) is a WordPress plugin with 23 published CVE records in this archive. The latest tracked vulnerability was published Aug 18, 2026; the highest published CVSS base score is 9.3.
geodirectoryCVE-2026-68565: GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.8.172. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Aug 18, 2026 |
CVE-2026-68565
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.8.172. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 11, 2026 |
CVE-2026-19091
GeoDirectory revision handling lets Subscribers delete arbitrary files
GeoDirectory through 2.8.169 exposes the geodir_auto_save_post and geodir_delete_revision AJAX actions with a geodir-save-post nonce. A Subscriber can place post_type=attachment only in the query string to bypass a check that inspects POST while the handlers consume the combined request. The attacker can convert an owned GeoDirectory auto-draft into an attachment and inject file paths into attachment metadata; later GeoDir_Post_Data::delete_revision() and wp_delete_post() dereference those paths and unlink the files. The exact attachment metadata subkeys are not disclosed.
|
2.8.170 |
CVE8.1
NVDPending
|
| Aug 09, 2026 |
CVE-2026-16988
GeoDirectory map markers disclose private listing locations
GeoDirectory before 2.8.169 does not authorize requests for map-marker data for a specified listing. An unauthenticated attacker can request a pending or draft listing and obtain its title and exact geographic coordinates. The CNA does not disclose the endpoint, listing identifier parameter, response format, or whether other listing fields are returned.
|
2.8.169 |
CVE7.5
NVDPending
|
| Aug 05, 2026 |
CVE-2026-16968
GeoDirectory contributor search exposes registered-user email addresses
GeoDirectory before 2.8.168 does not limit a user-search handler to callers with permission to list WordPress users. Any authenticated user with Contributor access or higher can query it and retrieve email addresses for all registered users, including administrators. This unscored record received deeper review because it exposes a low-privilege user-enumeration and contact-data primitive. The CNA does not disclose the handler, endpoint or search parameter.
|
2.8.168 |
CVE6.5
NVDPending
|
| Aug 05, 2026 |
CVE-2025-15677
GeoDirectory place-category setting permits editor-level stored XSS
GeoDirectory before 2.8.110 stores a place-category setting without adequate sanitization and later renders it on an administrative page without output escaping. An Editor or another high-privilege user who is not allowed unfiltered_html can persist JavaScript that executes when a privileged user opens the affected page. This unscored record received deeper review because stored XSS can reach an administrator, including in multisite configurations. The CNA does not disclose the setting name, submission action or administrative page.
|
2.8.110 |
CVE3.5
NVDPending
|
| Jul 02, 2026 |
CVE-2026-57681
GeoDirectory: Server-side request forgery
GeoDirectory is affected by server-side request forgery. Exploitation requires an authenticated subscriber account. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.8.161. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
2.8.162 |
CVE6.4
NVDPending
|
| Jun 26, 2026 |
CVE-2026-54831
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.162. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
2.8.163 |
CVE9.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39512
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.152. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
2.8.154 |
CVE9.3
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42671
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.157. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
2.8.158 |
CVE6.5
NVDPending
|
| Jan 23, 2026 |
CVE-2026-24549
GeoDirectory: Cross-site request forgery
GeoDirectory is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Nov 12, 2025 |
CVE-2025-12833
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: Broken access control
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by broken access control. Exploitation requires an authenticated author account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jul 26, 2025 |
CVE-2024-13507
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: SQL injection
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jul 11, 2025 |
CVE-2025-6200
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.9
NVDPending
|
| Feb 11, 2025 |
CVE-2024-13506
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: Cross-site scripting
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jan 02, 2025 |
CVE-2024-56259
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Nov 01, 2024 |
CVE-2024-43981
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Oct 28, 2024 |
CVE-2024-50437
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Aug 18, 2024 |
CVE-2024-43145
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.5
NVD8.8
|
| Apr 23, 2024 |
CVE-2024-3732
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: Cross-site scripting
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 28, 2023 |
CVE-2023-50845
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: SQL injection
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Feb 27, 2023 |
CVE-2023-0278
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Jan 23, 2023 |
CVE-2022-4775
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Oct 11, 2021 |
CVE-2021-24720
GeoDirectory Business Directory: Cross-site scripting
GeoDirectory Business Directory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD5.4
|