Geodirectory
by WordPress
Source repositories
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-12833 | Med | 0.21 | 4.3 | 0.00 | Nov 12, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user… | ||
| CVE-2024-43981 | Med | 0.21 | 4.3 | 0.00 | Nov 1, 2024 | Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70. | ||
| CVE-2026-57681 | Med | 0.00 | 6.4 | 0.00 | Jul 2, 2026 | Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions. | ||
| CVE-2026-54831 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. |
- risk 0.21cvss 4.3epss 0.00
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user…
- risk 0.21cvss 4.3epss 0.00
Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70.
- risk 0.00cvss 6.4epss 0.00
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
Page 2 of 2