Eklenti güvenlik geçmişi
GeoDirectory güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) GeoDirectory – WP Business Directory Plugin and Classified Listings Directory eklentisi için 27 açık kaydı bulunuyor; en yenisi 3 Ekim 2026 tarihli. Bunların 12 tanesi kritik veya yüksek önemde, 10 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 2.8.190.
- Toplam kayıt
- 27
- Kritik veya yüksek
- 12
- Oturumsuz istismar
- 10
- Son kayıt
- 3 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
SQL enjeksiyonu
Etkilenen sürümler: 2.8.186 ve öncesi · Oturum açmadan istismar edilebilir
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post=<pending-listing-id> and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Türkçe kayıt ve ne yapmalıdepolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.183 ve öncesi
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in all versions up to, and including, 2.8.183 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the AJAX save handler validates only post authorship and a nonce with no additional capability check, allowing any subscriber-level user who owns a listing to exploit this vulnerability.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.181 ve öncesi
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., 'phone') in all versions up to, and including, 2.8.181 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload must be stored in a text-type custom field (such as a phone field) via the AJAX geodir_save_post endpoint, using entity-encoded angle brackets (e.g., <img src=x onerror=alert(1)>) to bypass the strpos()-gated tag-stripping check.
SQL enjeksiyonu
Etkilenen sürümler: 2.8.174 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 2.8.176 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.173 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.
siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.172 ve öncesi
Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.
rastgele dosya silme
Etkilenen sürümler: 2.8.169 ve öncesi
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). By placing post_type=attachment exclusively in the query string to bypass the consistency check, an attacker can convert an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata, which the delete_revision handler then dereferences and unlinks without any post-type or path validation.
hassas bilgi ifşası
Etkilenen sürümler: 2.8.169 öncesi · Oturum açmadan istismar edilebilir
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.
hassas bilgi ifşası
Etkilenen sürümler: 2.8.168 öncesi
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.110 öncesi
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users such as editors and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in a multisite setup).
sunucu taraflı istek sahteciliği (SSRF)
Etkilenen sürümler: 2.8.161 ve öncesi
Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.
SQL enjeksiyonu
Etkilenen sürümler: 2.8.162 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
SQL enjeksiyonu
Etkilenen sürümler: 2.8.152 ve öncesi · Oturum açmadan istismar edilebilir
Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
eksik yetki denetimi
Etkilenen sürümler: 2.8.157 ve öncesi · Oturum açmadan istismar edilebilir
Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 2.8.149 ve öncesi · Oturum açmadan istismar edilebilir
Cross-Site Request Forgery (CSRF) vulnerability in Paolo GeoDirectory geodirectory allows Cross Site Request Forgery.This issue affects GeoDirectory: from n/a through <= 2.8.149.
yetkisiz nesne erişimi (IDOR)
Etkilenen sürümler: 2.8.139 ve öncesi
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places.
SQL enjeksiyonu
Etkilenen sürümler: 2.8.97 ve öncesi · Oturum açmadan istismar edilebilir
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.120 öncesi
The GeoDirectory WordPress plugin before 2.8.120 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.8.97 ve öncesi
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the display_name profile parameter in all versions up to, and including, 2.8.97 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.3.84 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through <= 2.3.84.
eksik yetki denetimi
Etkilenen sürümler: 2.3.70 ve öncesi
Missing Authorization vulnerability in AyeCode – WP Business Directory Plugins GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GeoDirectory: from n/a through 2.3.70.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.3.80 ve öncesi
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo GeoDirectory geodirectory allows Stored XSS.This issue affects GeoDirectory: from n/a through <= 2.3.80.
SQL enjeksiyonu
Etkilenen sürümler: 2.3.61 ve öncesi
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode Ltd GeoDirectory.This issue affects GeoDirectory: from n/a through 2.3.61.
SQL enjeksiyonu
Etkilenen sürümler: 2.2.24 öncesi
The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.2.22 öncesi
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
depolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 2.1.1.3 öncesi
The GeoDirectory Business Directory WordPress plugin before 2.1.1.3 was vulnerable to Authenticated Stored Cross-Site Scripting (XSS).
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.