PT-2025-30947 · WordPress · Classified Listings Directory Plugin+1

Michael Mazzolini

·

Published

2025-07-26

·

Updated

2025-07-26

·

CVE-2024-13507

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress versions prior to 2.8.98
Description The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is susceptible to time-based SQL Injection via the dist parameter. Insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries allow unauthenticated attackers to inject additional SQL queries, potentially extracting sensitive information from the database.
Recommendations Update to version 2.8.98 or later.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-13507

Affected Products

Classified Listings Directory Plugin
Geodirectory – Wp Business Directory Plugin