Impact
The GeoDirectory WordPress plugin fails to enforce authorization when serving map marker data for a requested listing. As a result, any visitor can retrieve the title and exact geographic coordinates of listings that are not yet published, even if they are pending or draft. This flaw allows an attacker to learn sensitive location and title information without authentication, potentially exposing confidential real‑world assets or business strategy.
Affected Systems
The vulnerability affects the GeoDirectory plugin, any WordPress installation that runs versions prior to 2.8.169. Users of the plugin who have not upgraded to the fixed release are at risk, regardless of whether they use the plugin alone or alongside other GeoDirectory‑related extensions.
Risk and Exploitability
No EPSS score is reported and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. However, the flaw is trivially exploitable via unauthenticated HTTP requests to the markers REST endpoint, yielding direct access to sensitive data. The lack of an authorization check means the attack can be performed by anyone who can reach the endpoint, making it a high‑impact data disclosure.
OpenCVE Enrichment