PT-2026-67988 · WordPress · Geodirectory
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GeoDirectory versions prior to 2.8.168
Description
An issue exists where a user-search handler is not properly restricted to users authorized to list users. This allows any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators, via the
geodir json search users function.Recommendations
Update GeoDirectory to version 2.8.168 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geodirectory