Impact
The GeoDirectory plugin accepts latitude and longitude values for a listing, stores them without numeric validation, and later interpolates those values directly into a distance calculation query. Because the query is executed by the public wp_ajax_nopriv_geodir_widget_listings handler when an attacker supplies a pending‑listing ID and requests sorting by distance, an authenticated user with Subscriber level or higher can inject additional SQL code. This injection (CWE‑89) allows the attacker to read arbitrary database tables and exfiltrate sensitive information such as user accounts or site configuration, potentially leading to a breach of confidentiality and data loss.
Affected Systems
All installations of the paoltaia:GeoDirectory WordPress plugin version 2.8.186 and earlier are vulnerable. The issue is present in the core plugin files and is not limited to a specific feature module. Users of any WordPress site running a patched or newer version of GeoDirectory are not affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity with moderate to high impact. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting that active exploitation has not been reported at the time of this analysis. Attackers must authenticate as a Subscriber or higher and must target the publicly accessible wp_ajax_nopriv_geodir_widget_listings endpoint while submitting set_post=<pending‑listing‑id> and sort_by=distance_asc. Once the injection succeeds, an attacker can execute arbitrary SELECT queries to retrieve sensitive data from the database.
OpenCVE Enrichment