Executive brief
GeoDirectory is a popular WordPress plugin used to build business directory and location-based websites. A CSRF vulnerability allows unauthenticated attackers to trick logged-in administrators or users into performing unintended actions—such as changing settings, adding malicious content, or deleting data—without their knowledge. This could lead to unauthorized modification of site configuration, content tampering, or account compromise.
Technical details
The vulnerability is a classic Cross-Site Request Forgery (CSRF) flaw in GeoDirectory versions up to 2.8.176 that fails to properly validate anti-CSRF tokens on sensitive operations. The vulnerability requires user interaction: an authenticated user must click a malicious link or visit a crafted webpage to trigger the attack. An unauthenticated attacker can craft a request that, when executed by a privileged user, performs state-changing actions within the plugin without the user's explicit consent. The vulnerability has been patched in version 2.8.177 and later.
Affected products
- GeoDirectory GeoDirectory <=2.8.176
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: Version 2.8.177 released with fix