Medium 5.3 Unfixed
2025-12-09≤ 8.9.4
CVE-2025-62109
Minimum safe version
8.7.4
Update to 8.7.4 or later to address 11 fixable vulnerabilities
CVE-2025-62109
CVE-2024-7381
CVE-2024-7380
CVE-2024-3591
CVE-2024-30451
CVE-2024-30227
Geo Controller <= 8.6.4 - Unauthenticated PHP Object Injection via shortcode REST API Route
CVE-2023-51513
WordPress Geo Controller Plugin < 8.5.3 is vulnerable to Cross Site Scripting (XSS)
Geo Controller <= 8.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WordPress Geolocation Plugin – CF Geo Plugin <= 7.13.11 - Reflected Cross-Site Scripting
CF Geo Plugin < 7.13.12 - Reflected Cross-Site Scripting