PT-2026-69265 · WordPress · Geodirectory
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GeoDirectory versions prior to 2.8.169
Description
The GeoDirectory WordPress plugin fails to perform authorization checks when returning map marker data for a single requested listing. This allows unauthenticated users to disclose the title and exact geographic coordinates of non-public listings, such as those in pending or draft status, via the markers REST endpoint.
Recommendations
Update to version 2.8.169 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geodirectory