VYPR

Events For Geodirectory

by WordPress

CVEs (2)

  • CVE-2026-39532HigJun 15, 2026
    risk 0.50cvss 8.8epss 0.00

    Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.

  • CVE-2026-11616HigJun 9, 2026
    risk 0.50cvss 8.8epss 0.00

    The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying strip_tags(esc_sql()) — with no allow-list — to the attacker-controlled…