Junglewise Threat Intelligence

CVE-2026-42671: Paolo GeoDirectory missing authorization in WordPress plugin

CVE-2026-42671 · Severity: medium · CVSS 6.5 · Published 2026-06-01

Technologies: AyeCode Ltd GeoDirectory. Vendors: AyeCode Ltd.

Executive brief

GeoDirectory is a WordPress plugin used to create business directories and location-based listings. A security flaw in the plugin allows unauthorized individuals to bypass access controls and perform actions they should not be permitted to do. This could lead to unauthorized changes to directory listings or disruption of the service, potentially impacting the integrity of the site's data and its reputation.

Technical details

The GeoDirectory plugin for WordPress (versions up to and including 2.8.157) is vulnerable to broken access control due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability stems from a failure to validate user permissions or implement proper nonce tokens before processing specific requests. Attackers can exploit this to modify data or impact the availability of the directory service. The issue is resolved in version 2.8.158.

Affected products

  • Paolo GeoDirectory <= 2.8.157

Timeline

  • 2026-04-13: other: Vulnerability reported by researcher Evan NR
  • 2026-05-13: advisory: Initial advisory published by Patchstack
  • 2026-06-01: disclosed: CVE published in NVD
  • 2026-05-13: patched: Version 2.8.158 released to address the issue

References

Related threats