Impact
Unauthenticated Cross Site Request Forgery (CSRF) occurs when an attacker crafts a request that a victim's browser submits, bypassing the plugin's authentication checks. This flaw exists in GeoDirectory plugin versions up to 2.8.176. The vulnerability is classified as CWE‑352. An attacker can leverage it to perform actions with the privileges of the logged‑in user, potentially creating or deleting listings, uploading content, or altering site settings, thereby compromising the integrity and availability of the WordPress site.
Affected Systems
Systems impacted are environments running WordPress with the GeoDirectory plugin up to and including version 2.8.176. The plugin is developed by the GeoDirectory team. No specific minor revisions beyond 2.8.176 are mentioned, so all releases at or before that version are vulnerable.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Exploitation requires only that a victim with administrative or privileged access to the WordPress instance views a crafted URL or loads a malicious resource that triggers a state‑changing request to the plugin. Because the attack is unauthenticated and relies on the victim's browser, an attacker can send the request from a remote domain without needing credentials, making the threat realistic for sites that accept traffic from untrusted users.
OpenCVE Enrichment