← WordPress Vulnerabilities
WordPress security by component

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory creates business directories and classified listings with locations, categories, search, filters, maps, and user submissions.

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (geodirectory) is a WordPress plugin with 23 published CVE records in this archive. The latest tracked vulnerability was published Aug 18, 2026; the highest published CVSS base score is 9.3.

Plugin slug: geodirectory

CVE-2026-68565: GeoDirectory: Cross-site scripting

GeoDirectory is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.8.172. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedAug 18, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for geodirectory
Safe version
Aug 18, 2026 CVE-2026-68565
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.8.172. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Aug 11, 2026 CVE-2026-19091
GeoDirectory revision handling lets Subscribers delete arbitrary files
GeoDirectory through 2.8.169 exposes the geodir_auto_save_post and geodir_delete_revision AJAX actions with a geodir-save-post nonce. A Subscriber can place post_type=attachment only in the query string to bypass a check that inspects POST while the handlers consume the combined request. The attacker can convert an owned GeoDirectory auto-draft into an attachment and inject file paths into attachment metadata; later GeoDir_Post_Data::delete_revision() and wp_delete_post() dereference those paths and unlink the files. The exact attachment metadata subkeys are not disclosed.
2.8.170
CVE8.1
NVDPending
Aug 09, 2026 CVE-2026-16988
GeoDirectory map markers disclose private listing locations
GeoDirectory before 2.8.169 does not authorize requests for map-marker data for a specified listing. An unauthenticated attacker can request a pending or draft listing and obtain its title and exact geographic coordinates. The CNA does not disclose the endpoint, listing identifier parameter, response format, or whether other listing fields are returned.
2.8.169
CVE7.5
NVDPending
Aug 05, 2026 CVE-2026-16968
GeoDirectory contributor search exposes registered-user email addresses
GeoDirectory before 2.8.168 does not limit a user-search handler to callers with permission to list WordPress users. Any authenticated user with Contributor access or higher can query it and retrieve email addresses for all registered users, including administrators. This unscored record received deeper review because it exposes a low-privilege user-enumeration and contact-data primitive. The CNA does not disclose the handler, endpoint or search parameter.
2.8.168
CVE6.5
NVDPending
Aug 05, 2026 CVE-2025-15677
GeoDirectory place-category setting permits editor-level stored XSS
GeoDirectory before 2.8.110 stores a place-category setting without adequate sanitization and later renders it on an administrative page without output escaping. An Editor or another high-privilege user who is not allowed unfiltered_html can persist JavaScript that executes when a privileged user opens the affected page. This unscored record received deeper review because stored XSS can reach an administrator, including in multisite configurations. The CNA does not disclose the setting name, submission action or administrative page.
2.8.110
CVE3.5
NVDPending
Jul 02, 2026 CVE-2026-57681
GeoDirectory: Server-side request forgery
GeoDirectory is affected by server-side request forgery. Exploitation requires an authenticated subscriber account. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is n/a through 2.8.161. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
2.8.162
CVE6.4
NVDPending
Jun 26, 2026 CVE-2026-54831
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.162. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
2.8.163
CVE9.3
NVDPending
Jun 15, 2026 CVE-2026-39512
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 2.8.152. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
2.8.154
CVE9.3
NVDPending
Jun 01, 2026 CVE-2026-42671
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.8.157. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
2.8.158
CVE6.5
NVDPending
Jan 23, 2026 CVE-2026-24549
GeoDirectory: Cross-site request forgery
GeoDirectory is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
Nov 12, 2025 CVE-2025-12833
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: Broken access control
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by broken access control. Exploitation requires an authenticated author account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending
Jul 26, 2025 CVE-2024-13507
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: SQL injection
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.5
NVDPending
Jul 11, 2025 CVE-2025-6200
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.9
NVDPending
Feb 11, 2025 CVE-2024-13506
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory: Cross-site scripting
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVDPending
Jan 02, 2025 CVE-2024-56259
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVD5.4
Nov 01, 2024 CVE-2024-43981
GeoDirectory: A security weakness
GeoDirectory is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVD8.8
Oct 28, 2024 CVE-2024-50437
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVD5.4
Aug 18, 2024 CVE-2024-43145
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.5
NVD8.8
Apr 23, 2024 CVE-2024-3732
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: Cross-site scripting
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.4
NVD5.4
Dec 28, 2023 CVE-2023-50845
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: SQL injection
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.6
NVD7.2
Feb 27, 2023 CVE-2023-0278
GeoDirectory: SQL injection
GeoDirectory is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE7.2
NVD7.2
Jan 23, 2023 CVE-2022-4775
GeoDirectory: Cross-site scripting
GeoDirectory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.4
NVD5.4
Oct 11, 2021 CVE-2021-24720
GeoDirectory Business Directory: Cross-site scripting
GeoDirectory Business Directory is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVEPending
NVD5.4