Junglewise Threat Intelligence

CVE-2026-84813: WordPress GeoDirectory SQL injection

CVE-2026-84813 · Severity: critical · CVSS 9.3 · Published 2026-09-03

Vendors: WordPress.org.

Executive brief

GeoDirectory is a popular WordPress plugin that enables directory listings and location-based content on websites. An unauthenticated SQL injection vulnerability in versions up to 2.8.174 allows attackers to read, modify, or delete the entire database including user accounts and sensitive business data without requiring any login credentials or user interaction.

Technical details

A SQL injection vulnerability exists in WordPress GeoDirectory plugin versions up to 2.8.174 that can be exploited without authentication. The vulnerability allows attackers to execute arbitrary SQL queries against the database through unsanitized input. With network access to an affected WordPress installation, an unauthenticated attacker can retrieve sensitive data, modify database records, or delete content entirely. The vulnerability has been patched in version 2.8.175 and later; immediate update is recommended.

Affected products

  • WordPress.org GeoDirectory <= 2.8.174

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Fixed in version 2.8.175
  • kev added: Known to be exploited in the wild

References