Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesGeoDirectory

GeoDirectory vulnerabilities

GeoDirectory has 16 known vulnerabilities in this database. The most recent published record is dated 3 Oct 2026.

Known vulnerabilities
16
Active installs
10,000+
Latest version
2.8.186
Last updated
30 Sep 2026
Most recent
3 Oct 2026

No fixed version has been published yet, so consider disabling, removing or replacing the plugin until a safe release is available.

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
SQL injection
CVE-2026-103913
High 7.5Up to 2.8.186No fixed version yet4 d ago
Cross-site scripting (XSS)
CVE-2026-96766
Medium 6.4Up to 2.8.183Fixed in a later version (latest 2.8.186)12 d ago
Cross-site scripting (XSS)
CVE-2026-93897
Medium 6.4Up to 2.8.181Fixed in a later version (latest 2.8.186)12 d ago
Remote code execution
CVE-2026-19091
High 8.1Up to 2.8.169Fixed in a later version (latest 2.8.186)11 Aug 2026
Sensitive data exposure
CVE-2026-16988
High 7.5Before 2.8.169Fixed in 2.8.1699 Aug 2026
Sensitive data exposure
CVE-2026-16968
Medium 6.5Before 2.8.168Fixed in 2.8.1685 Aug 2026
Cross-site scripting (XSS)
CVE-2025-15677
Low 3.5Before 2.8.110Fixed in 2.8.1105 Aug 2026
Broken access control
CVE-2025-12833
Medium 4.3Up to 2.8.139Fixed in a later version (latest 2.8.186)12 Nov 2025
SQL injection
CVE-2024-13507
High 7.5Up to 2.8.97Fixed in a later version (latest 2.8.186)26 Jul 2025
Cross-site scripting (XSS)
CVE-2025-6200
Medium 5.9Before 2.8.120Fixed in 2.8.12011 Jul 2025
Cross-site scripting (XSS)
CVE-2024-13506
Medium 6.4Up to 2.8.97Fixed in a later version (latest 2.8.186)11 Feb 2025
Cross-site scripting (XSS)
CVE-2024-3732
Medium 6.4Before 2.3.49Fixed in 2.3.4923 Apr 2024
SQL injection
CVE-2023-50845
High 7.6Up to 2.3.28Fixed in a later version (latest 2.8.186)28 Dec 2023
SQL injection
CVE-2023-0278
High 7.2Before 2.2.24Fixed in 2.2.2427 Feb 2023
Cross-site scripting (XSS)
CVE-2022-4775
Medium 5.4Before 2.2.22Fixed in 2.2.2223 Jan 2023
Cross-site scripting (XSS)
CVE-2021-24720
Medium 5.4Before 2.1.1.3Fixed in 2.1.1.311 Oct 2021
Read the published descriptions
CVE-2026-103913, 3 Oct 2026
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post=<pending-listing-id> and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-96766, 25 Sep 2026
The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the AJAX save handler validates only post authorship and a nonce with no additional capability check, allowing any subscriber-level user who owns a listing to exploit this vulnerability. CVE record
CVE-2026-93897, 25 Sep 2026
The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all versions up to, and including, 2.8.181 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload must be stored in a text-type custom field (such as a phone field) via the AJAX geodir_save_post endpoint, using entity-encoded angle brackets (e.g., &lt;img src=x onerror=alert(1)&gt;) to bypass the strpos()-gated tag-stripping check. CVE record
CVE-2026-19091, 11 Aug 2026
The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). By placing post_type=attachment exclusively in the query string to bypass the consistency check, an attacker can convert an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata, which the delete_revision handler then dereferences and unlinks without any post-type or path validation. CVE record
CVE-2026-16988, 9 Aug 2026
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings. CVE record
CVE-2026-16968, 5 Aug 2026
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators. CVE record
CVE-2025-15677, 5 Aug 2026
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup). CVE record
CVE-2025-12833, 12 Nov 2025
The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places. CVE record
CVE-2024-13507, 26 Jul 2025
The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2025-6200, 11 Jul 2025
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. CVE record
CVE-2024-13506, 11 Feb 2025
The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-3732, 23 Apr 2024
The GeoDirectory - WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gd_single_tabs' shortcode in all versions up to, and including, 2.3.48 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2023-50845, 28 Dec 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory - WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory - WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28. CVE record
CVE-2023-0278, 27 Feb 2023
The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. CVE record
CVE-2022-4775, 23 Jan 2023
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. CVE record
CVE-2021-24720, 11 Oct 2021
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS). CVE record

What to do if you run GeoDirectory

If you run GeoDirectory, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new GeoDirectory vulnerabilities

Free. We email you when a new vulnerability is published for GeoDirectory, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support