Impact
The GeoDirectory WordPress plugin is missing an authorization check in its user-search handler geodir_json_search_users. This allows any authenticated user who has Contributor or higher privileges to force the plugin to return the email addresses of all registered users, including site administrators. The primary consequence is the unauthorized disclosure of sensitive contact information that can be used for further attacks or social engineering. The vulnerability is an example of a failure to enforce proper access control and results in information exposure.
Affected Systems
All installations of the GeoDirectory WordPress plugin with a version earlier than 2.8.168 are affected. The vulnerability applies to sites running this plugin and is not limited to a specific WordPress version. Based on the description, it is inferred that any user with Contributor, Author, Editor, or Administrator WordPress roles can exploit the flaw.
Risk and Exploitability
Because the vulnerability requires only authentication and grants the unprivileged Contributor role, a wide range of users can exploit it. No exploit has been reported in the wild, and the EPSS score is currently unavailable, indicating no known exploitation activity. The flaw is not listed in the CISA KEV catalog, suggesting it has not yet become a target of mass exploitation. Nonetheless, the potential to expose administrator emails warrants prompt remediation.
OpenCVE Enrichment