SecAlerts
g

geodirectory

Security Risk Profile

49
/100
medium

Security Risk Score

Comprehensive risk assessment based on 13 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 23, 2024 to present

13
Total CVEs
6
Critical+High
0
Exploited
6
Unpatched

Threat Assessment

Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
6
Critical/High
Risk Level
49/100
medium

Severity Distribution

Critical
0
High
6
Medium
6
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
5
2
Infoleak
2
3
Path Traversal
1
4
SSRF
1
5
SQL Injection
1

Most Affected Products

1. GeoDirectory GeoDirectory3
2. GeoDirectory WordPress plugin2
3. GeoDirectory Events Calendar for GeoDirectory2
4. GeoDirectory WP Business Directory Plugin and Classified Listings Directory2
5. AyeCode Geodirectory Wordpress2

Recent Vulnerabilities

See more →
CVE-2026-66604
CVSS 7.1high

WordPress GeoDirectory plugin <= 2.8.173 - Cross Site Scripting (XSS) vulnerability

Aug 20, 2026🔧 No Patch
CVE-2026-19091
CVSS 8.1high

GeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision

Aug 11, 2026🔧 No Patch
CVE-2026-16988
CVSS 7.5high

GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint

Aug 9, 2026🔧 No Patch
CVE-2025-15677
CVSS 3.5low

GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories

Aug 5, 2026🔧 No Patch
CVE-2026-16968
CVSS 6.5medium

GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users

Aug 5, 2026🔧 No Patch
CVE-2026-57681
CVSS 6.4medium

WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF) vulnerability

Jul 2, 2026🔧 No Patch
CVE-2026-39532
CVSS 8.8high

WordPress Events Calendar for GeoDirectory plugin <= 2.3.25 - PHP Object Injection vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-11616
CVSS 8.8high

Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege Escalation

Jun 9, 2026🔧 No Patch
CVE-2025-12833
CVSS 4.3medium

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing Authorization to Authenticated (Author+) Arbitrary Image Attachment

Nov 12, 2025🔧 No Patch
CVE-2024-13507
CVSS 7.5high

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection

Jul 26, 2025🔧 No Patch

Monitor geodirectory in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.