CVE-2026-103913: high-severity vulnerability in paoltaia GeoDirectory – WP Business Directory…
GeoDirectory <= 2.8.186 - Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post=<pending-listing-id> and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
paoltaia · GeoDirectory – WP Business Directory Plugin and Classified Listings DirectoryRelated CVEs — paoltaia GeoDirectory – WP Business Directory…
In the same product, most dangerous first.
CVE-2026-19091HIGHGeoDirectory <= 2.8.169 - Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revisionEPSS 1.1%CVE-2024-13507HIGHGeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL InjectionEPSS 0.5%CVE-2024-13506MEDIUMGeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display_name ParameterEPSS 0.4%CVE-2024-3732MEDIUMGeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_tabs' ShortcodeEPSS 0.3%CVE-2025-12833MEDIUMGeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing Authorization to Authenticated (Author+) Arbitrary Image AttachmentEPSS 0.2%CVE-2026-93897MEDIUMGeoDirectory <= 2.8.181 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone')EPSS 0.2%
References
https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/class-geodir-ajax.php#L1464https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/class-geodir-post-data.php#L660https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/general-functions.php#L1312https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/general-functions.php#L1394https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/widgets/class-geodir-widget-listings.php#L862https://plugins.trac.wordpress.org/changeset?reponame=&old=3723536%40geodirectory&new=3723536%40geodirectoryhttps://www.wordfence.com/threat-intel/vulnerabilities/id/54f449f4-0a22-45c7-8a3b-9121d70b5fe4?source=cve