What is CVE-2026-16988?
The GeoDirectory WordPress plugin before version 2.8.169 lacks an authorization check when returning map marker data for a single listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings. This vulnerability exposes sensitive location data, and it is recommended to update the plugin to version 2.8.169 or higher immediately.
Azərbaycanca: GeoDirectory WordPress plugin-in 2.8.169 versiyasından əvvəlki versiyalarında icazə yoxlaması olmadığı üçün autentifikasiya olunmamış istifadəçilər qeyri-ictimai (gözləmədə və ya qaralama) elanların başlığını və dəqiq coğrafi koordinatlarını əldə edə bilər. Bu zəiflik həssas məkan məlumatlarının ifşasına səbəb olur, plugin-i dərhal 2.8.169 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What data can be disclosed by the CVE-2026-16988 vulnerability in the GeoDirectory plugin?
This vulnerability allows unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.
To which version should the GeoDirectory plugin be updated to protect against CVE-2026-16988?
It is recommended to update the plugin to version 2.8.169 or higher immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.