Vulnerabilities and security researches forgeodirectory geodirectory
Direction: ascendingJun 06, 2024
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2024-3732
- CVE, Research URL
- Home page URL
- Date
- Apr 23, 2024
- Research Description
- The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gd_single_tabs' shortcode in all versions up to, and including, 2.3.48 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.3.49.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2023-0278
- CVE, Research URL
- Home page URL
- Date
- Feb 27, 2023
- Research Description
- The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
- Affected versions
-
max 2.2.24.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2021-24720
- CVE, Research URL
- Home page URL
- Date
- Oct 11, 2021
- Research Description
- The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
- Affected versions
-
max 2.1.1.3.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2023-50845
- CVE, Research URL
- Home page URL
- Date
- Dec 29, 2023
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28.
- Affected versions
-
max 2.3.29.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2022-4775
- CVE, Research URL
- Home page URL
- Date
- Jan 23, 2023
- Research Description
- The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
- Affected versions
-
max 2.2.22.
- Status
-
vulnerable
Aug 11, 2024
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2024-43145
- CVE, Research URL
- Home page URL
- Date
- Aug 19, 2024
- Research Description
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3.61.
- Affected versions
-
max 2.3.62.
- Status
-
vulnerable
Sep 01, 2024
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2024-43981
- CVE, Research URL
- Home page URL
- Date
- Nov 01, 2024
- Research Description
- Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70.
- Affected versions
-
max 2.3.71.
- Status
-
vulnerable
Oct 28, 2024
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2024-50437
- CVE, Research URL
- Home page URL
- Date
- Oct 29, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through <= 2.3.80.
- Affected versions
-
max 2.3.81.
- Status
-
vulnerable
Jan 03, 2025
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2024-56259
- CVE, Research URL
- Home page URL
- Date
- Jan 02, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through <= 2.3.84.
- Affected versions
-
max 2.3.85.
- Status
-
vulnerable
Feb 12, 2025
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2024-13506
- CVE, Research URL
- Home page URL
- Date
- Feb 11, 2025
- Research Description
- The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 2.8.98.
- Status
-
vulnerable
Jul 30, 2025
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2024-13507
- CVE, Research URL
- Home page URL
- Date
- Jul 26, 2025
- Research Description
- The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 2.8.98.
- Status
-
vulnerable
Dec 10, 2025
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2025-12833
- CVE, Research URL
- Home page URL
- Date
- Nov 12, 2025
- Research Description
- The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places.
- Affected versions
-
max 2.8.140.
- Status
-
vulnerable
Jan 28, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-24549
- CVE, Research URL
- Home page URL
- Date
- Jan 23, 2026
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Paolo GeoDirectory geodirectory allows Cross Site Request Forgery.This issue affects GeoDirectory: from n/a through <= 2.8.149.
- Affected versions
-
max 2.8.150.
- Status
-
vulnerable
Apr 23, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-39512
- CVE, Research URL
- Home page URL
- Date
- Jun 16, 2026
- Research Description
- Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
- Affected versions
-
max 2.8.154.
- Status
-
vulnerable
Apr 25, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2025-6200
- CVE, Research URL
- Home page URL
- Date
- Jul 11, 2025
- Research Description
- The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected versions
-
max 2.8.120.
- Status
-
vulnerable
May 22, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-42671
- CVE, Research URL
- Home page URL
- Date
- Jun 01, 2026
- Research Description
- Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.
- Affected versions
-
max 2.8.158.
- Status
-
vulnerable
Jun 16, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # 5eca4bfed9c9d992a7e65a3ccf60f59a4ab4039b
- CVE, Research URL
- Home page URL
- Date
- Dec 20, 2022
- Research Description
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] < 2.2.20 GeoDirectory <= 2.2.19 - CSV Injection The GeoDirectory plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.19. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
- Affected versions
-
max 2.2.20.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # 26accc39270de25eb30316fdbbd24e92f9dbb883
- CVE, Research URL
- Home page URL
- Date
- Dec 21, 2022
- Research Description
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] < 2.2.20 WordPress GeoDirectory Plugin <= 2.2.19 is vulnerable to CSV Injection Update the WordPress GeoDirectory plugin to the latest available version (at least 2.2.20). Wordfence discovered and reported this CSV Injection vulnerability in WordPress GeoDirectory Plugin. This could allow a malicious actor to craft malicious formulas to then exploit vulnerabilities in the spreadsheet software or to execute commands to gain access to the victim';s PC. This vulnerability has been fixed in version 2.2.20.
- Affected versions
-
max 2.2.20.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # 7946eeed92659407b0e0b9f3d1dd6e3076958a2a
- CVE, Research URL
- Home page URL
- Date
- Oct 18, 2023
- Research Description
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] < 2.3.29 GeoDirectory <= 2.3.28 - Authenticated (Administrator+) SQL Injection via orderby The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 2.3.29.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # 08b4972e-d647-4cab-96f6-52bf6e63f712
- CVE, Research URL
- Home page URL
- Date
- -
- Research Description
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory [geodirectory] < 2.3.29 GeoDirectory < 2.3.29 - Authenticated (Administrator+) SQL Injection via orderby The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
- Affected versions
-
max 2.3.29.
- Status
-
vulnerable
Jun 25, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-54831
- CVE, Research URL
- Home page URL
- Date
- Jun 26, 2026
- Research Description
- Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
- Affected versions
-
max 2.8.163.
- Status
-
vulnerable
Jul 04, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-57681
- CVE, Research URL
- Home page URL
- Date
- Jul 02, 2026
- Research Description
- Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
- Affected versions
-
max 2.8.162.
- Status
-
vulnerable
Aug 07, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2025-15677
- CVE, Research URL
- Home page URL
- Date
- Aug 05, 2026
- Research Description
- The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
- Affected versions
-
max 2.8.110.
- Status
-
vulnerable
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-16968
- CVE, Research URL
- Home page URL
- Date
- Aug 05, 2026
- Research Description
- The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
- Affected versions
-
max 2.8.168.
- Status
-
vulnerable
Aug 10, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-16988
- CVE, Research URL
- Home page URL
- Date
- Aug 09, 2026
- Research Description
- The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.
- Affected versions
-
max 2.8.169.
- Status
-
vulnerable
Aug 13, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-19091
- CVE, Research URL
- Home page URL
- Date
- Aug 12, 2026
- Research Description
- The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). By placing post_type=attachment exclusively in the query string to bypass the consistency check, an attacker can convert an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata, which the delete_revision handler then dereferences and unlinks without any post-type or path validation.
- Affected versions
-
max 2.8.170.
- Status
-
vulnerable
Aug 29, 2026
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory # CVE-2026-81271
- CVE, Research URL
- Home page URL
- Date
- Aug 27, 2026
- Research Description
- Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
- Affected versions
-
max 2.8.177.
- Status
-
vulnerable