GeoDirectory WordPress Plugin Unauthenticated SQL Injection

Release Date: 3rd September 2026 (Added 8th September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations, System/Network administrators, and website teams that operate a WordPress site using the GeoDirectory business-directory plugin. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-84813 is a critical, unauthenticated SQL injection vulnerability in GeoDirectory, a WordPress business-directory and classified-listings plugin maintained by AyeCode Ltd with over 10,000 active installations and more than 2.5 million downloads since it was first published in 2014. The vulnerability allows an attacker to inject arbitrary SQL into a database query without needing to authenticate to the WordPress site at all. GeoDirectory has a history of similar SQL injection reports (including issues affecting versions 2.2.24, 2.3.28, and 2.3.61), making this a recurring weakness class in the plugin rather than an isolated one-off.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-84813
  2. https://wordpress.org/plugins/geodirectory/