HomeWordPress vulnerabilitiesGeoDirectory
GeoDirectory vulnerabilities
GeoDirectory has 16 known vulnerabilities in this database. The most recent published record is dated 3 Oct 2026.
- Known vulnerabilities
- 16
- Active installs
- 10,000+
- Latest version
- 2.8.186
- Last updated
- 30 Sep 2026
- Most recent
- 3 Oct 2026
No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| SQL injection CVE-2026-103913 | High 7.5 | Up to 2.8.186 | No fixed version yet | 4 d ago |
| Cross-site scripting (XSS) CVE-2026-96766 | Medium 6.4 | Up to 2.8.183 | Fixed in a later version (latest 2.8.186) | 12 d ago |
| Cross-site scripting (XSS) CVE-2026-93897 | Medium 6.4 | Up to 2.8.181 | Fixed in a later version (latest 2.8.186) | 12 d ago |
| Remote code execution CVE-2026-19091 | High 8.1 | Up to 2.8.169 | Fixed in a later version (latest 2.8.186) | 11 Aug 2026 |
| Sensitive data exposure CVE-2026-16988 | High 7.5 | Before 2.8.169 | Fixed in 2.8.169 | 9 Aug 2026 |
| Sensitive data exposure CVE-2026-16968 | Medium 6.5 | Before 2.8.168 | Fixed in 2.8.168 | 5 Aug 2026 |
| Cross-site scripting (XSS) CVE-2025-15677 | Low 3.5 | Before 2.8.110 | Fixed in 2.8.110 | 5 Aug 2026 |
| Broken access control CVE-2025-12833 | Medium 4.3 | Up to 2.8.139 | Fixed in a later version (latest 2.8.186) | 12 Nov 2025 |
| SQL injection CVE-2024-13507 | High 7.5 | Up to 2.8.97 | Fixed in a later version (latest 2.8.186) | 26 Jul 2025 |
| Cross-site scripting (XSS) CVE-2025-6200 | Medium 5.9 | Before 2.8.120 | Fixed in 2.8.120 | 11 Jul 2025 |
| Cross-site scripting (XSS) CVE-2024-13506 | Medium 6.4 | Up to 2.8.97 | Fixed in a later version (latest 2.8.186) | 11 Feb 2025 |
| Cross-site scripting (XSS) CVE-2024-3732 | Medium 6.4 | Before 2.3.49 | Fixed in 2.3.49 | 23 Apr 2024 |
| SQL injection CVE-2023-50845 | High 7.6 | Up to 2.3.28 | Fixed in a later version (latest 2.8.186) | 28 Dec 2023 |
| SQL injection CVE-2023-0278 | High 7.2 | Before 2.2.24 | Fixed in 2.2.24 | 27 Feb 2023 |
| Cross-site scripting (XSS) CVE-2022-4775 | Medium 5.4 | Before 2.2.22 | Fixed in 2.2.22 | 23 Jan 2023 |
| Cross-site scripting (XSS) CVE-2021-24720 | Medium 5.4 | Before 2.1.1.3 | Fixed in 2.1.1.3 | 11 Oct 2021 |
Read the published descriptions
- CVE-2026-103913, 3 Oct 2026
- The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post=<pending-listing-id> and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-96766, 25 Sep 2026
- The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the AJAX save handler validates only post authorship and a nonce with no additional capability check, allowing any subscriber-level user who owns a listing to exploit this vulnerability. CVE record
- CVE-2026-93897, 25 Sep 2026
- The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all versions up to, and including, 2.8.181 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload must be stored in a text-type custom field (such as a phone field) via the AJAX geodir_save_post endpoint, using entity-encoded angle brackets (e.g., <img src=x onerror=alert(1)>) to bypass the strpos()-gated tag-stripping check. CVE record
- CVE-2026-19091, 11 Aug 2026
- The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). By placing post_type=attachment exclusively in the query string to bypass the consistency check, an attacker can convert an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata, which the delete_revision handler then dereferences and unlinks without any post-type or path validation. CVE record
- CVE-2026-16988, 9 Aug 2026
- The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings. CVE record
- CVE-2026-16968, 5 Aug 2026
- The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators. CVE record
- CVE-2025-15677, 5 Aug 2026
- The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup). CVE record
- CVE-2025-12833, 12 Nov 2025
- The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places. CVE record
- CVE-2024-13507, 26 Jul 2025
- The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2025-6200, 11 Jul 2025
- The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
- CVE-2024-13506, 11 Feb 2025
- The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-3732, 23 Apr 2024
- The GeoDirectory - WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gd_single_tabs' shortcode in all versions up to, and including, 2.3.48 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2023-50845, 28 Dec 2023
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory - WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory - WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28. CVE record
- CVE-2023-0278, 27 Feb 2023
- The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. CVE record
- CVE-2022-4775, 23 Jan 2023
- The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE record
- CVE-2021-24720, 11 Oct 2021
- The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). CVE record
What to do if you run GeoDirectory
If you run GeoDirectory, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new GeoDirectory vulnerabilities
Free. We email you when a new vulnerability is published for GeoDirectory, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.