| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-12833 | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing Authorization to Authenticated (Author+) Arbitrary Image Attachment | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | Medium | 4.3 | 2025-11-12 04:29:09 | Deep Dive |
| CVE-2024-13507 | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | High | 7.5 | 2025-07-26 03:38:18 | Deep Dive |
| CVE-2024-13506 | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Display_name Parameter | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | Medium | 6.4 | 2025-02-11 11:10:04 | Deep Dive |
| CVE-2024-3732 | GeoDirectory – WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_tabs' Shortcode | paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | Medium | 6.4 | 2024-04-23 09:32:55 | Deep Dive |