GeoDirectory <= 2.8.119 - Authenticated (Contributor+) Stored Cross-Site Scripting
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Minimum safe version
2.8.154
Update to 2.8.154 or later to address 19 fixable vulnerabilities
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.152 - Unauthenticated SQL Injection
CVE-2026-24549
CVE-2025-12833
CVE-2024-13507
CVE-2024-13506
WordPress GeoDirectory Plugin <= 2.3.84 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-50437
CVE-2024-43981
CVE-2024-43145
CVE-2024-3732
GeoDirectory < 2.3.29 - Authenticated (Administrator+) SQL Injection via orderby
WordPress GeoDirectory Plugin <= 2.3.28 is vulnerable to SQL Injection
GeoDirectory <= 2.3.28 - Authenticated (Administrator+) SQL Injection via orderby
CVE-2023-0278
CVE-2022-4775
WordPress GeoDirectory Plugin <= 2.2.19 is vulnerable to CSV Injection
GeoDirectory <= 2.2.19 - CSV Injection
CVE-2021-24720