Executive brief
GeoDirectory is a WordPress plugin used to create location-based business directories. A security flaw allows an unauthenticated attacker to interact directly with the website's database. This could lead to the theft of sensitive customer information, site data, or a partial disruption of services.
Technical details
A SQL injection vulnerability exists in the GeoDirectory plugin for WordPress in versions up to and including 2.8.162. The flaw is caused by improper neutralization of special elements used in SQL commands (CWE-89), allowing an unauthenticated attacker to execute arbitrary SQL queries via the network. This can result in unauthorized data retrieval from the database or limited service disruption. The vulnerability has been addressed in version 2.8.163.
Affected products
- Paolo GeoDirectory <= 2.8.162
Timeline
- 2026-06-05: disclosed: Reported by manop55555
- 2026-06-17: advisory: Patchstack advisory published
- 2026-06-26: patched: Version 2.8.163 released to address the issue