Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
CVE-2026-16968
Description
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/d7a4e3ee-507d-44fb-9386-27ad67158cdc/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.