CVE-2025-12833

MEDIUM

GeoDirectory - WP Business Directory Plugin <2.8.139 - Insecure Dir...

Title source: llm
STIX 2.1

Description

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 11.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
paoltaia/GeoDirectory – WP Business Directory Plugin and Classified Listings Directory < 2.8.139
Published Nov 12, 2025
Tracked Since Feb 18, 2026