CVE-2026-84813: WordPress GeoDirectory plugin <= 2.8.174 - SQL Injection vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
Affected Software
1 affected component
WordPress GeoDirectory<=2.8.174
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GeoDirectory pluginto a version that resolves this vulnerability.Fixed in 2.8.175
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need a WordPress account or user interaction to exploit this issue?
No. The vulnerability is unauthenticated and is rated as network-accessible with low attack complexity; no user interaction is required.
2
How can I determine whether my site is affected?
Check the installed GeoDirectory plugin version. Versions 2.8.174 and earlier are identified as affected.
3
What is the expected security impact if exploitation succeeds?
The provided severity vector indicates high confidentiality impact and low availability impact. It does not indicate an integrity impact.