PT-2026-69265 · WordPress · Geodirectory

·

CVE-2026-16988

·

Published

2026-08-09

·

Updated

2026-08-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GeoDirectory versions prior to 2.8.169
Description The GeoDirectory WordPress plugin fails to perform authorization checks when returning map marker data for a single requested listing. This allows unauthenticated users to disclose the title and exact geographic coordinates of non-public listings, such as those in pending or draft status, via the markers REST endpoint.
Recommendations Update to version 2.8.169 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16988

Affected Products

Geodirectory