Executive brief
GeoDirectory is a popular WordPress plugin that provides local business directory functionality. An unauthenticated attacker can inject malicious scripts into the site that compromise visitor data, hijack user accounts, or redirect users to malicious sites. The vulnerability requires user interaction (such as clicking a link) but poses a significant risk to all site visitors.
Technical details
A cross-site scripting (XSS) vulnerability exists in GeoDirectory plugin versions 2.8.173 and earlier that allows unauthenticated attackers to inject arbitrary JavaScript into the web application. The vulnerability requires user interaction, such as clicking a malicious link or visiting a crafted page. An attacker can exploit this to steal session cookies, perform actions on behalf of users, or harvest sensitive data. The vulnerability is fixed in version 2.8.174 and later.
Affected products
- GeoDirectory GeoDirectory ≤ 2.8.173
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Fixed in version 2.8.174