WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in GeoDirectory – WP Business Directory Plugin and Classified Listings Directory

A superb WordPress Business Directory plugin to create a local business directory, classified ads directory, or job listings board.

26Reported vulnerabilities
9.9Highest CVSS score
2.8.172Latest version
10,000+Active installs

What to do now

Update GeoDirectory – WP Business Directory Plugin and Classified Listings Directory to 2.8.177 or later. 26 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 14, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-6200 Medium 5.9 0.2% Before 2.8.120 2.8.120 July 11, 2025
CVE-2024-43145 Critical 9.9 0.4% 2.3.61 and earlier 2.3.62 August 7, 2024
CVE-2021-24720 Medium 5.4 0.9% Before 2.1.1.3 2.1.1.3 October 11, 2021
CVE-2022-4775 Medium 5.4 0.5% Before 2.2.22 2.2.22 January 23, 2023
CVE-2026-19091 High 8.1 0.8% 0 to 2.8.169 (inclusive) 2.8.170 August 11, 2026
CVE-2026-54831 High 7.5 0.4% 2.8.162 and earlier 2.8.163 June 17, 2026
CVE-2026-39512 High 7.5 0.3% 2.8.152 and earlier 2.8.154 April 13, 2026
CVE-2024-13507 High 7.5 0.4% 0 to 2.8.97 (inclusive) 2.8.98 July 26, 2025
CVE-2023-0278 High 7.2 0.8% 0 up to (but not including) 2.2.24 2.2.24 February 27, 2023
CVE-2023-50845 High 7.2 0.5% 2.3.28 and earlier 2.3.29 December 28, 2023
CVE-2026-66604 High 7.2 0.2% 2.8.173 and earlier 2.8.174 August 19, 2026
WF-3bcd61d4-4775-4297-b7f5-664991fcd6d2 High 7.2 2.3.28 and earlier 2.3.29 October 18, 2023
CVE-2024-13506 Medium 6.4 0.4% 0 to 2.8.97 (inclusive) 2.8.98 February 11, 2025
CVE-2024-56259 Medium 6.4 0.3% 2.3.84 and earlier 2.3.85 December 30, 2024
CVE-2026-68565 Medium 6.4 0.2% 2.8.177 and earlier 2.8.178 August 18, 2026
CVE-2026-57681 Medium 6.4 0.2% 2.8.161 and earlier 2.8.162 June 30, 2026
CVE-2024-50437 Medium 6.4 0.2% 2.3.80 and earlier 2.3.81 October 24, 2024
CVE-2024-3732 Medium 5.4 0.3% Before 2.3.49 2.3.49 April 23, 2024
CVE-2026-16988 Medium 5.3 0.3% 2.8.168 and earlier 2.8.169 August 3, 2026
CVE-2026-42671 Medium 5.3 0.2% 2.8.157 and earlier 2.8.158 May 13, 2026
CVE-2026-81271 Medium 4.3 0.2% 2.8.176 and earlier 2.8.177 August 26, 2026
CVE-2025-15677 Medium 4.4 0.2% 2.8.109 and earlier 2.8.110 July 28, 2026
CVE-2026-16968 Medium 4.3 0.2% 2.8.167 and earlier 2.8.168 July 27, 2026
CVE-2026-24549 Medium 4.3 0.1% 2.8.149 and earlier 2.8.150 January 23, 2026
CVE-2025-12833 Medium 4.3 0.2% 0 to 2.8.139 (inclusive) 2.8.140 November 12, 2025
WF-ee11d9e5-64d5-49b4-b5f5-b76605250028 Medium 4.1 2.2.19 and earlier 2.2.20 December 20, 2022

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.