CVE-2026-66604: WordPress GeoDirectory plugin <= 2.8.173 - Cross Site Scripting (XSS) vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
Affected Software
1 affected component
GeoDirectory GeoDirectory<=2.8.173
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GeoDirectory Pluginto a version that resolves this vulnerability.Fixed in 2.8.174
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which GeoDirectory versions are affected?
GeoDirectory versions 2.8.173 and earlier are affected.
2
Does exploitation require an authenticated WordPress account?
No. The vulnerability is described as unauthenticated, so an attacker does not need a WordPress account or prior privileges. Exploitation does require user interaction.
3
What impact can successful exploitation have?
The supplied severity vector indicates low potential impact to confidentiality, integrity, and availability, with the impact scope extending beyond the vulnerable component.