← Terug naar overzicht

A critical unauthenticated SQL injection vulnerability has been identified in the GeoDirectory WordPress plugin affecting versions 2.8.174 and below. The flaw allows unauthenticated attackers to inject malicious SQL queries, potentially exposing sensitive database information or enabling unauthorized data manipulation. No authentication is required to exploit this vulnerability, making it particularly dangerous for sites running affected versions. The vulnerability has been assigned CVE-2026-84813 and is tracked by both NVD and Patchstack. WordPress site administrators using GeoDirectory are strongly advised to update to a patched version immediately. The current risk level is rated High due to the unauthenticated nature of the exploit and the potential for significant data exposure.

Affected products

  • GeoDirectory WordPress Plugin <= 2.8.174

Related CVE's

  • CVE-2026-84813

Categories

  • Database & Storage
  • Web Technologies