Impact
An unauthenticated SQL Injection vulnerability exists in the WordPress GeoDirectory plugin for versions up to 2.8.174. Attackers can inject arbitrarily crafted SQL statements through the plugin’s input parameters, enabling data exfiltration, manipulation, or complete takeover of the site’s database. This flaw represents a classic data‑handling weakness identified as CWE‑89.
Affected Systems
WordPress installations that employ the GeoDirectory plugin version 2.8.174 or earlier are affected. No other vendors or products are listed as impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity level, and the vulnerability is unauthenticated, which raises the likelihood of exploitation if the plugin’s endpoints are publicly reachable. EPSS data is not available, so the precise exploitation probability remains unknown, yet the lack of required credentials increases risk. The plugin is not catalogued in the CISA KEV list. Based on the description, the attack vector is inferred to be via unauthenticated web requests to the plugin’s endpoints.
OpenCVE Enrichment