Extension WordPress
Vulnérabilités GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Cette page rassemble les failles publiées pour GeoDirectory – WP Business Directory Plugin and Classified Listings Directory, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
20 fiches
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.161 – Authenticated (Subscriber+) Server-Side Request Forgery
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.161. This makes it possible for authenticated attackers, with Subscriber-level access…
*-2.8.161
2.8.162
30/06/2026
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.162 – Unauthenticated SQL Injection
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.162 due to insufficient escaping on the user supplied parameter and lack of…
*-2.8.162
2.8.163
17/06/2026
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.157 – Missing Authorization
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.8.157. This makes it…
*-2.8.157
2.8.158
13/05/2026
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.152 – Unauthenticated SQL Injection
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.152 due to insufficient escaping on the user supplied parameter and lack of…
*-2.8.152
2.8.154
13/04/2026
GeoDirectory <= 2.8.149 – Cross-Site Request Forgery
The GeoDirectory plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.149. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…
*-2.8.149
2.8.150
23/01/2026
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 – Missing Authorization to Authenticated (Author+) Arbitrary Image Attachment
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on…
*-2.8.139
2.8.140
11/11/2025
GeoDirectory <= 2.8.119 – Authenticated (Contributor+) Stored Cross-Site Scripting
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gd_best_of' shortcode in all versions up to, and including, 2.8.119 due to insufficient input sanitization…
*-2.8.119
2.8.120
20/06/2025
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 – Authenticated (Subscriber+) Stored Cross-Site Scripting via Display_name Parameter
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization…
*-2.8.97
2.8.98
10/02/2025
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 – Unauthenticated SQL Injection
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the…
*-2.8.97
2.8.98
29/01/2025
GeoDirectory <= 2.3.84 – Authenticated (Contributor+) Stored Cross-Site Scripting
The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.3.84
2.3.85
30/12/2024
GeoDirectory <= 2.3.80 – Authenticated (Contributor+) Stored Cross-Site Scripting
The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.80 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.3.80
2.3.81
24/10/2024
GeoDirectory <= 2.3.70 – Missing Authorization via geodirectory_rated()
The GeoDirectory plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the geodirectory_rated() function in versions up to, and including, 2.3.70. This makes it possible for authenticated attackers, with subscriber-level…
*-2.3.70
2.3.71
28/08/2024
GeoDirectory <= 2.3.61 – Authenticated (Subscriber+) SQL Injection
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the geodir_total_listings_count function in versions up to, and including, 2.3.61 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-2.3.61
2.3.62
07/08/2024
GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_tabs' Shortcode
The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gd_single_tabs' shortcode in all versions up to, and including, 2.3.48 due to insufficient input sanitization and…
*-2.3.48
2.3.49
22/04/2024
GeoDirectory <= 2.3.28 – Authenticated(Administrator+) SQL Injection
The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.3.29 (exclusive) due to insufficient escaping on the user supplied parameter…
[*, 2.3.29)
2.3.29
21/12/2023
GeoDirectory <= 2.3.28 – Authenticated (Administrator+) SQL Injection via orderby
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-2.3.28
2.3.29
18/10/2023
GeoDirectory <= 2.2.23 – Authenticated (Admin+) SQL Injection
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the 'selected', 'post_type' parameters in versions up to, and including, 2.2.23 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-2.2.23
2.2.24
31/01/2023
GeoDirectory <= 2.2.21 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The GeoDirectory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.2.21 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-2.2.21
2.2.22
29/12/2022
GeoDirectory <= 2.2.19 – CSV Injection
The GeoDirectory plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.19. This allows administrator-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files…
*-2.2.19
2.2.20
20/12/2022
GeoDirectory <= 2.1.1.2 – Authenticated (admin+) Stored Cross-Site Scripting
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
*-2.1.1.2
2.1.1.3
02/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.