CVE-2026-16988
GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.
| Vendor | unknown |
| Product | geodirectory |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown geodirectory
Be the first to know when new unknown vulnerabilities affecting unknown geodirectory are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / GeoDirectory
0 < 2.8.169
References
Credits
Usama Arshad WPScan