CVE-2026-16968
GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.
| Vendor | unknown |
| Product | geodirectory |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown geodirectory
Be the first to know when new unknown vulnerabilities affecting unknown geodirectory are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / GeoDirectory
0 < 2.8.168
References
Credits
Vaibhav Narkhede WPScan