Access violation vulnerability in GeoDirectory – WP Business Directory Plugin and Classified Listings Directory 2.8.139

A popular plugin for WordPress called “GeoDirectory – WP Business Directory Plugin and Classified Listings Directory” has a security issue. This problem, called “Insecure Direct Object Reference”, affects all versions of the plugin up to 2.8.139. It happens because the plugin does not check the user’s information properly. This means that someone who is logged in and has author-level access or higher can add any image file they want to any location on the website.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.