Executive brief
GeoDirectory, a WordPress plugin used to create business directories, is vulnerable to a security flaw that allows authenticated users to make the server perform unauthorized web requests. An attacker with a basic 'Subscriber' account could use this to probe internal network services or access sensitive information that is not publicly available. This could lead to internal data exposure or be used as a stepping stone for further attacks on the organization's infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the GeoDirectory plugin for WordPress (versions up to and including 2.8.161). The flaw is classified as CWE-918 and stems from insufficient validation of user-supplied URLs, allowing the server to execute requests to arbitrary domains. An attacker authenticated with Subscriber-level privileges can exploit this to scan internal networks, interact with internal services, or bypass firewalls. The vulnerability has been addressed in version 2.8.162.
Affected products
- Paolo GeoDirectory <= 2.8.161
Timeline
- 2026-05-16: disclosed: Reported by dodoh4t
- 2026-06-30: advisory: Patchstack published advisory
- 2026-07-02: patched: NVD publication and patch availability confirmed in version 2.8.162