WordPress · Geodirectory · CVE-2025-6200
**Name of the Vulnerable Software and Affected Versions:**
GeoDirectory WordPress plugin versions prior to 2.8.120
**Description:**
The GeoDirectory WordPress plugin does not validate or escape certain shortcode attributes before displaying them within a page or post. This could allow users with contributor-level access or higher to perform stored cross-site scripting (XSS) attacks.
**Recommendations:**
Update the GeoDirectory WordPress plugin to version 2.8.120 or later.