What is CVE-2026-16968?
The GeoDirectory WordPress plugin before version 2.8.168 has an unrestricted user-search handler that allows any authenticated user with Contributor-level or higher access to retrieve email addresses of all registered users, including administrators. Updating to the latest version is strongly recommended.
Azərbaycanca: GeoDirectory WordPress plaqini (2.8.168 əvvəl) 'user-search handler' funksiyasında məhdudiyyət olmadığına görə, Contributor və daha yüksək səviyyəli hər hansı autentifikasiya olunmuş istifadəçi bütün qeydiyyatlı istifadəçilərin, o cümlədən administratorların e-poçt ünvanlarını əldə edə bilər. Plaqini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
From which user level can the GeoDirectory plugin leak users' email information?
The vulnerability affects any authenticated user with Contributor-level or higher access.
What measure is recommended to resolve this issue?
Updating the plugin to the latest version (2.8.168 or higher) is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.