Impact
Based on the description, this vulnerability allows an authenticated subscriber to cause the WordPress server to fetch arbitrary URLs, enabling information disclosure, internal network scanning, or data exfiltration. The flaw resides in the GeoDirectory plugin, identified as CWE-918, and pertains to SSRF with subscriber-level access.
Affected Systems
The issue affects the GeoDirectory plugin for WordPress developed by Paolo and applies to all installed versions up to and including 2.8.161; WordPress sites running any of these plugin versions are vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, a very low EPSS score (<1%) shows limited likelihood of exploitation, and the vulnerability is not listed in CISA KEV, suggesting no widely known exploits. Based on the description, the attack vector is remote, requiring a crafted request to the plugin endpoint, and is limited to authenticated subscribers, therefore the risk is confined to sites that allow subscriber-level users to interact with GeoDirectory features.
OpenCVE Enrichment