Impact
The GeoDirectory plugin contains a missing authorization flaw that permits users to access or modify data and perform actions beyond their privileges. This weakness—classified as CWE‑862—is caused by incorrectly configured access control security levels, as identified in the CVE description. The impact is the potential for unauthorized access to protected functionality or data within the plugin.
Affected Systems
WordPress sites running the GeoDirectory plugin version 2.8.157 or earlier are affected. The flaw is present in all plugin releases from early versions through 2.8.157, meaning any installation of those versions is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score is not available, so the exact exploitation probability is unknown. The CVE does not provide details on the attack vector or specific conditions required for exploitation, but the missing authorization flaw could allow an attacker to access plugin functions that should be restricted. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at this time.
OpenCVE Enrichment