Impact
The GeoDirectory WordPress plugin is missing an authorization check in its user-search handler geodir_json_search_users. This allows any authenticated user who has Contributor or higher privileges to force the plugin to return the email addresses of all registered users, including site administrators. The primary consequence is the unauthorized disclosure of sensitive contact information that can be used for further attacks or social engineering. The vulnerability is an example of a failure to enforce proper access control and results in information exposure.
Affected Systems
All installations of the GeoDirectory WordPress plugin with a version earlier than 2.8.168 are affected. The vulnerability applies to sites running this plugin and is not limited to a specific WordPress version. Based on the description, it is inferred that any user with Contributor, Author, Editor, or Administrator WordPress roles can exploit the flaw.
Risk and Exploitability
Because the vulnerability requires only authentication and grants the unprivileged Contributor role, a wide range of users can exploit it. The EPSS score is < 1% and the CVSS score of 6.5 denotes medium severity. The flaw is not listed in the CISA KEV catalog. Nevertheless, the potential to expose administrator emails warrants prompt remediation.
OpenCVE Enrichment