Executive brief
GeoDirectory is a popular WordPress plugin that enables directory listings and location-based content on websites. An unauthenticated SQL injection vulnerability in versions up to 2.8.174 allows attackers to read, modify, or delete the entire database including user accounts and sensitive business data without requiring any login credentials or user interaction.
Technical details
A SQL injection vulnerability exists in WordPress GeoDirectory plugin versions up to 2.8.174 that can be exploited without authentication. The vulnerability allows attackers to execute arbitrary SQL queries against the database through unsanitized input. With network access to an affected WordPress installation, an unauthenticated attacker can retrieve sensitive data, modify database records, or delete content entirely. The vulnerability has been patched in version 2.8.175 and later; immediate update is recommended.
Affected products
- WordPress.org GeoDirectory <= 2.8.174
Timeline
- 2026-09-03: disclosed
- 2026-09-02: patched: Fixed in version 2.8.175
- kev added: Known to be exploited in the wild