PT-2025-29209 · WordPress · Geodirectory

Imduyb

·

Published

2025-07-11

·

Updated

2025-07-11

·

CVE-2025-6200

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: GeoDirectory WordPress plugin versions prior to 2.8.120
Description: The GeoDirectory WordPress plugin does not validate or escape certain shortcode attributes before displaying them within a page or post. This could allow users with contributor-level access or higher to perform stored cross-site scripting (XSS) attacks.
Recommendations: Update the GeoDirectory WordPress plugin to version 2.8.120 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-6200

Affected Products

Geodirectory