Unknown Geodirectory vulnerabilities
3 known vulnerabilities affecting unknown/geodirectory.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-6200MEDIUMCVSS 5.9fixed in 2.8.1202025-07-11
CVE-2025-6200 [MEDIUM] CWE-79 CVE-2025-6200: The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
cvelistv5nvd
CVE-2023-0278HIGHCVSS 7.2fixed in 2.2.242023-02-27
CVE-2023-0278 [HIGH] CWE-89 CVE-2023-0278: The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter be
The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
cvelistv5nvd
CVE-2022-4775MEDIUMCVSS 5.4fixed in 2.2.222023-01-23
CVE-2022-4775 [MEDIUM] CWE-79 CVE-2022-4775: The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode a
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
cvelistv5nvd