This page aggregates publicly disclosed CVE and security risk information related to wpgeodirectory, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-26967 | Deserialization of Untrusted Data vulnerability in Stiofan Events Calendar for GeoDirectory events-for-geodirectory allows Object Injection.This issue affects Events Calendar for GeoDirectory: from n/a through <= 2.3.14. | [email protected] | 8.8 | 0.34% | 2025-03-03 | 2026-04-23 |
| CVE-2023-0278 | The GeoDirectory WordPress plugin before 2.2.24 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | [email protected] | 7.2 | 0.73% | 2023-02-27 | 2025-03-10 |