CVE-2026-16988: GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16988?
The severity of CVE-2026-16988 is rated at 45, indicating a moderate risk due to information leakage.
How do I fix CVE-2026-16988?
To fix CVE-2026-16988, update the GeoDirectory WordPress plugin to version 2.8.169 or later.
What type of vulnerability is CVE-2026-16988?
CVE-2026-16988 is an information leakage vulnerability allowing unauthorized disclosure of pending or draft listings.
Who is affected by CVE-2026-16988?
Users of the GeoDirectory WordPress plugin prior to version 2.8.169 are affected by CVE-2026-16988.
What data can be disclosed due to CVE-2026-16988?
CVE-2026-16988 allows unauthenticated users to disclose the title and exact geographic coordinates of non-public listings.