CVE-2026-16968: GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GeoDirectory (WordPress plugin)to a version that resolves this vulnerability.Fixed in 2.8.168
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16968?
CVE-2026-16968 has a risk score of 48, indicating a moderate security concern.
How do I fix CVE-2026-16968?
To address CVE-2026-16968, update the GeoDirectory plugin to version 2.8.168 or higher.
Who is affected by CVE-2026-16968?
CVE-2026-16968 affects any WordPress site using GeoDirectory plugin versions before 2.8.168.
What type of vulnerability is CVE-2026-16968?
CVE-2026-16968 is classified as an information disclosure vulnerability.
What impact does CVE-2026-16968 have on user privacy?
CVE-2026-16968 allows authenticated users with Contributor-level access or higher to access the email addresses of all registered users.