CVE-2026-57681: WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF) vulnerability
Published Jul 2, 2026
·Updated
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
Affected Software
1 affected component
GeoDirectory GeoDirectory<=2.8.161
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GeoDirectory pluginto a version that resolves this vulnerability.Fixed in 2.8.162
Event History
Jul 2, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57681?
The severity of CVE-2026-57681 is rated as medium with a score of 6.4.
2
What type of vulnerability is CVE-2026-57681?
CVE-2026-57681 is classified as a Server Side Request Forgery (SSRF) vulnerability.
3
How do I fix CVE-2026-57681?
To fix CVE-2026-57681, update the GeoDirectory plugin to version 2.8.162 or later.
4
Who is affected by CVE-2026-57681?
CVE-2026-57681 affects users of the GeoDirectory plugin versions 2.8.161 and below.
5
What are the potential impacts of CVE-2026-57681?
The potential impacts of CVE-2026-57681 include unauthorized access to internal services and exposure of sensitive information.