SQL Injection Vulnerability in GeoDirectory – WP Business Directory Plugin
CVE-2024-13507

7.5HIGH

What is CVE-2024-13507?

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is susceptible to a time-based SQL Injection vulnerability. This arises from insufficient escaping of the user-supplied 'dist' parameter and inadequate preparation within the SQL queries, allowing unauthenticated attackers to manipulate existing queries. Exploiting this flaw enables them to append additional SQL commands, potentially leading to unauthorized access to sensitive database information.

Affected Version(s)

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory * <= 2.8.97

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Mazzolini
.
CVE-2024-13507 : SQL Injection Vulnerability in GeoDirectory – WP Business Directory Plugin