SecAlerts
geodirectory logo

geodirectory

Security Risk Profile

52
/100
medium

Security Risk Score

Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from April 23, 2024 to present

10
Total CVEs
3
Critical+High
0
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
52/100
medium
🆕 2Fresh (<7d)📈 2 in Last 30 Days

Severity Distribution

Critical
0
High
3
Medium
5
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
XSS
4
2
Infoleak
1
3
SSRF
1
4
SQL Injection
1

Most Affected Products

1. GeoDirectory GeoDirectory2
2. GeoDirectory Events Calendar for GeoDirectory2
3. GeoDirectory WP Business Directory Plugin and Classified Listings Directory2
4. AyeCode Geodirectory Wordpress2
5. GeoDirectory WordPress plugin1

Recent Vulnerabilities

See more →
CVE-2025-15677
unknown

GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories

8/5/2026🔧 No Patch
CVE-2026-16968
unknown

GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users

8/5/2026🔧 No Patch
CVE-2026-57681
CVSS 6.4medium

WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF) vulnerability

7/2/2026🔧 No Patch
CVE-2026-39532
CVSS 8.8high

WordPress Events Calendar for GeoDirectory plugin <= 2.3.25 - PHP Object Injection vulnerability

6/15/2026🔧 No Patch
CVE-2026-11616
CVSS 8.8high

Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege Escalation

6/9/2026🔧 No Patch
CVE-2025-12833
CVSS 4.3medium

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing Authorization to Authenticated (Author+) Arbitrary Image Attachment

11/12/2025🔧 No Patch
CVE-2024-13507
CVSS 7.5high

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection

7/26/2025🔧 No Patch
CVE-2025-6200
CVSS 5.9EPSS 0%medium

GeoDirectory < 2.8.120 - Contributor+ Stored XSS

7/11/2025🔧 No Patch
CVE-2024-13506
CVSS 6.4medium

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display_name Parameter

2/11/2025🔧 No Patch
CVE-2024-3732
CVSS 6.4EPSS 0%medium

GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_tabs' Shortcode

4/23/2024

Monitor geodirectory in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.