SQL Injection Vulnerability in GeoDirectory β WP Business Directory Plugin
CVE-2024-13507
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 26 July 2025
What is CVE-2024-13507?
The GeoDirectory β WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is susceptible to a time-based SQL Injection vulnerability. This arises from insufficient escaping of the user-supplied 'dist' parameter and inadequate preparation within the SQL queries, allowing unauthenticated attackers to manipulate existing queries. Exploiting this flaw enables them to append additional SQL commands, potentially leading to unauthorized access to sensitive database information.
Affected Version(s)
GeoDirectory β WP Business Directory Plugin and Classified Listings Directory * <= 2.8.97