CVE-2025-12833

Published
View on NVD ↗
CVSS v3
4.3
MEDIUM
CVSS v2
N/A
Affected
2
PROJECTS

Description

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.139 via the 'post_attachment_upload' function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with author-level access and above, to attach arbitrary image files to arbitrary places.

GeoDirectory is the leading Directory Plugin for WordPress. Compatible with Gutenberg and the most popular page builders such as Elementor, Oxygen, Beaver Builder and Divi. GeoDirectory is the only solution for WordPress that can scale to millions of listings and high traffic.
GitHubGitHub
42
<blockquote> <p>👉 <strong><a href="https://wordpress.org/support/topic/best-directory-plugin-14/" rel="ugc">Best directory plugin</a></strong><br /> ⭐⭐⭐⭐⭐<br /> <em>I’ve tried many directory plugin before going for this one and i have to say this is by far the best one on the market.</em><br /> <em>it takes some time to learn how to use it and set it properly but once you do everything runs smooth and easy.</em><br /> <em>A special note goes to the support which is amazing and always reliable.</em><br /> 💁 mm81 (@mm81)</p> </blockquote> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/qoyDh3IfPOU?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span> <p>GeoDirectory is an outstanding WordPress Business Directory Plugin. It helps visitors to your Geo Directory website discover businesses through their listings.</p> <p>No matter what you need to build, be it a City Directory, a Job Board, a Real Estate listing directory, or a classified website, GeoDirectory turns any WordPress theme into a robust search network for users.</p> <p>Add all your business listings at once and tap into an impressive set of blocks, shortcodes, and widgets to set up intuitive, location-based website directories.</p> <p>Do it all stress-free and in style with 100% compatible WordPress page builders like Gutenberg (Kadence WP, Astra, Neve, OceanWP), Elementor, Bricks, Divi, Beaver Builder, and Breakdance!</p> <p>✅ <a href="https://demos.ayecode.io/" rel="nofollow ugc">Demos</a> ✅ <a href="https://wpgeodirectory.com/downloads/category/addons/" rel="nofollow ugc">Addons</a> ✅ <a href="https://wpgeodirectory.com/downloads/category/themes/" rel="nofollow ugc">Themes</a> ✅ <a href="https://wpgeodirectory.com/documentation/" rel="nofollow ugc">Docs</a> ✅ <a href="https://wpgeodirectory.com/category/showcase/" rel="nofollow ugc">Showcase</a></p> <h3>⚡ A PROFESSIONAL WORDPRESS BUSINESS DIRECTORY PLUGIN</h3> <p>GeoDirectory is a robust and scalable WordPress directory plugin. It offers advanced features tailored for listing websites. Its intuitive design and extensive customizability make it a top choice for professionals seeking a reliable WordPress directory solution.</p> <h3>⚡ HIGHLY RATED WORDPRESS BUSINESS DIRECTORY PLUGIN WITH OVER 585 FIVE-STAR REVIEWS</h3> <h4>READ WHAT USERS SAY ABOUT OUR WORDPRESS BUSINESS DIRECTORY PLUGIN</h4> <blockquote> <p>👉 <strong><a href="https://wordpress.org/support/topic/superb-plugin-410/" rel="ugc">Superb plugin!</a></strong><br /> ⭐⭐⭐⭐⭐<br /> <em>Look no further than this plugin for a directory website, it’s fantastic. I looked at Directorist first and spent a good amount of time setting that up to find out their search function only checked the post title and &gt;none of the tags or categories. Useless! GeoDirectory of course checks pretty much every field so your users can find every listing with ease.</em></p> <p><em>But that’s a relatively small plus point. The main selling point is the customization you can achieve. You can build your own layout using a page builder and insert the various fields wherever you see fit. It’s &gt;so flexible and if you run into a support issue, the team are always on hand to help with responses in just a few hours (and at weekends).</em></p> <p><em>You will need to invest some money to buy all the necessary add-ons that make this plugin so powerful, and you will need to spend a good amount of time working out how to build it how you want it, but it’s well worth it, and the results speak for themselves.</em></p> <p><em>There is documentation to help you set everything up and I think the team will admit it does lack in places but when you get quick support responses, it’s not an issue.</em></p> <p><em>Overall this is the perfect choice if you’re thinking of building a directory site. No need to look elsewhere.</em><br /> 💁 mparsons501979 (@mparsons501979)</p> <p>👉 <strong><a href="https://wordpress.org/support/topic/unbelievable-plugin-11/" rel="ugc">Unbelievable plugin</a></strong><br /> ⭐⭐⭐⭐⭐<br /> <em>This is the first business directory plugin I’ve ever used and I’m amazed about what it can do. I had reviewed several other directory plugins, but this one serves all of my purposes. There are so many options available for everything imaginable. They also have tons of add-ons to do even more that are part of the membership package I signed up for. Something like this normally would cost tens of thousands to have this much functionality. I highly recommend. Their customer service is very responsive as well and knowledgeable.</em><br /> 💁 beantown123 (@beantown123)</p> </blockquote> <h3>🔥 OUTSTANDING ELEMENTOR DIRECTORY PLUGIN INTEGRATION 🔥</h3> <p>GeoDirectory excels as a Directory Plugin for Elementor, seamlessly integrating with both the free Elementor Plugin and Elementor PRO.</p> <p>Utilize our widgets as Elementor Elements and enjoy a super-tight integration with Elementor PRO.</p> <p>Customize GeoDirectory Templates using Elementor PRO&#8217;s theme builder and leverage GeoDirectory Data with Elementor&#8217;s Dynamic Data feature.</p> <p>Watch this video to see how effortlessly you can customize business directory templates with GeoDirectory, the premier Elementor Directory Plugin:</p> <p>👉<a href="https://www.youtube.com/watch?v=fEdOOucOtUg" rel="nofollow ugc">Customize the design of GeoDirectory Templates with Elementor Pro</a></p> <h3>⚡ BE THE GO-TO GUIDING HAND FOR PROFESSIONALS: SAY HELLO TO OUR POWERFUL WORDPRESS BUSINESS DIRECTORY PLUGIN</h3> <p>Our dedicated team continuously refines every point of the search process (since 2011!), so your visitors always walk away with a productive session on GeoDirectory.</p> <h3>⚡ SCALE YOUR DIRECTORY WITH A RELIABLE, PROFICIENT DATABASE</h3> <p>For millions of listings and massive traffic, choose GeoDirectory— A WordPress directory plugin built for a global scale without issues. Our superior, optimized database architecture effortlessly handles any scale, guaranteed.</p> <h3>⚡ ASK AND YOU SHALL RECEIVE &#8211; DELIVER SPEEDY RESULTS</h3> <p>Our rapid search engine instantly delivers local business listings, offering free and paid options with the Price Manager add-on. Featuring a user-friendly interface and efficient back-end settings, our platform ensures top performance for your directory website.</p> <h3>⚡ DEVELOPER-FRIENDLY + COUNTLESS OF DIRECTORY THEMES</h3> <p>The design of your online directory website is limitless, with a wide array of themes and handy page-builder integrations. Need to add that personal touch? Developers can build on GeoDirectory freely using hooks (actions and filters).</p> <h3>⚡ QUICK SETUP GUIDE &#8211; FREE WORDPRESS BUSINESS DIRECTORY PLUGIN</h3> <p>GeoDirectory, a leading WordPress directory plugin, offers a streamlined setup with its feature-rich toolkit.</p> <ol> <li> <p><strong>Create your local directory</strong>. Quickly build with top page builders like Gutenberg, focusing on local or expanding globally with our premium add-on.</p> </li> <li> <p><strong>Publish your listing form</strong>. Allow front-end submissions with GeoDirectory&#8217;s drag-and-drop form builder, featuring over 40 field types and customizable fields. Include extended operating hours for businesses.</p> </li> <li> <p><strong>Bulk upload listings</strong>. Easily populate your directory via CSV for listings, categories, and reviews. Edit offline and auto-update with re-imports.</p> </li> <li> <p><strong>Enhance UX with 40+ widgets, shortcodes, and blocks</strong>. Improve visibility with Google Maps, monitor with Analytics, and support multilingual sites. Enable reviews and inquiries.</p> </li> <li> <p>** Improve search with filters **. Use filters for proximity, rating, and more to accelerate finding the right listings. Use badges to highlight listings.</p> </li> <li> <p><strong>Moderate listings smoothly</strong>. Manage submissions and categories efficiently with our back-end tools.</p> </li> </ol> <h3>⚡ USAGE OF WORDPRESS BUSINESS DIRECTORY PLUGINS</h3> <p>Transform your WordPress site into a versatile search engine for any sector with our free WordPress directory plugin, suitable for any business:</p> <ul> <li> <p><strong>Events Directory</strong> Turn your site into an event calendar with our FREE <a href="https://wordpress.org/plugins/events-for-geodirectory/" title="Adds an events manager to your directory" rel="ugc">Events for GeoDirectory add-on</a>, which is perfect for listing city events.</p> </li> <li> <p><strong>Real Estate Directory</strong> Display real estate listings, including houses and apartments, and manage agent profiles linking them to their listings.</p> </li> <li> <p><strong>Classifieds Ads Directory</strong> With GeoDirectory, create a marketplace for classified ads for selling cars, job finding, or service promotion.</p> </li> <li> <p><strong>Jobs Directory</strong> Build a job board where companies list vacancies and job seekers find opportunities with GeoDirectory.</p> </li> <li> <p><strong>Restaurants Directory</strong> Develop an online food directory to feature top restaurants, detailed menus, and reviews.</p> </li> <li> <p><strong>Hotels Directory</strong> List and manage hotels, resorts, and accommodation info with GeoDirectory.</p> </li> <li> <p><strong>Doctors Directory</strong> Easily set up a directory of doctors searchable by specialty and location using GeoDirectory.</p> </li> <li> <p><strong>Therapists Directory</strong> Create a directory for therapists, from massage professionals to psychologists.</p> </li> <li> <p><strong>Pets Directory</strong> Address the booming pet industry&#8217;s needs with a directory for veterinarians, pet stores, and more.</p> </li> <li> <p><strong>Church Directory</strong> Catalog churches, religious retreats, events, or member directories.</p> </li> <li> <p><strong>Service Directory</strong>A directory for digital freelancers (like Fiverr) or home service pros (like Angi).</p> </li> <li> <p><strong>Travel Directory</strong> In touristic areas, list attractions and offer curated experiences.</p> </li> <li> <p><strong>Hiking Trails Directory</strong> Target local traffic and niche enthusiasts by listing hiking trails..</p> </li> <li> <p><strong>Bars &amp; Nightlife Directory</strong> Drive high traffic and profits by cataloging bars, clubs, and nightlife events, facilitating ticket sales.</p> </li> <li> <p><strong>Software review sites</strong> As niche software review directories emerge in response to expanding market leaders, start your specialized site.</p> </li> </ul> <p>Because GeoDirectory allows you to create any listing type, each with unique custom fields, you can use GeoDirectory for virtually any kind of directory.</p> <h3>⚡ TAKE YOUR BUSINESS DIRECTORY TO NEW HEIGHTS WITH PREMIUM ADD-ONS.</h3> <p>Get instant access to Premium Add-Ons that can turn your local directory into a money-making global directory toolkit.</p> <ul> <li> <p><a href="https://wpgeodirectory.com/downloads/location-manager/" title="Allows to create a global directory" rel="nofollow ugc">Go wide with the Location Manager</a> &#8211; Create a global directory with accessible local business information of organizations in different countries, regions, cities, and neighborhoods.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/pricing-manager/" title="Allows to monetize your directory" rel="nofollow ugc">Set listing prices with the Pricing Manager</a> &#8211; Manage bids, taxes, and invoices for your top business listings with our free <a href="https://wordpress.org/plugins/invoicing/" title="Invoicing plugin for WordPress" rel="ugc">Invoicing Plugin</a>. Enable/disable features per price.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/custom-post-types/" title="Allows to extend your directory categorization" rel="nofollow ugc">Purpose your directory with Custom Post Types</a> &#8211; Create additional content types like events, coupons, and offers to supplement multiple directories and help businesses get noticed. Offer the &#8220;location-less&#8221; option to filter for online companies and websites.</p> </li> <li> <p><a href="https://wordpress.org/plugins/events-for-geodirectory/" title="Adds an events manager to your directory" rel="ugc">Add events as a business listing option (NOW FREE)</a> &#8211; Have people submit events and turn your GeoDirectory into a WordPress event calendar plugin. With the CPT add-on installed, create as many event post types as needed.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/multiratings-and-reviews/" title="Allows you to extend your rating and review categorization" rel="nofollow ugc">Give viewers a rundown on a company&#8217;s performance with MultiRatings and Reviews</a> -Extend the review system to allow multiple rating categories (e.g., service, quality, price), add images to reviews, and have other cool features.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/advanced-search-filters/" title="Allows you to extend the search with custom filters" rel="nofollow ugc">Enhance search with advanced search filters</a> -Turn any custom field into an advanced filter of the search widget for more accurate listings search. Adds AJAX search, smart autocompletes, geo-location, and much more.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/buddypress-integration/" title="integrates Buddypress with GeoDirectory" rel="nofollow ugc">Build up a priceless community with the Buddypress Integration</a> &#8211; Engage users and form a community around your niche and listings with seamless integration with Buddypress (open-source social networking software package).</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/claim-manager/" title="Allows users to claim their business" rel="nofollow ugc">Hand over some editorial power to business owners with the Claim Listing Manager</a> &#8211; Allow professionals to fine-tune their listings, add images, link to events, and show an &#8216;owner-verified&#8217; badge on the listing. Now, with the force upgrade/paid option.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/marker-cluster/" title="To avoid overcrowded maps" rel="nofollow ugc">Spot &amp; pinpoint businesses easier with Marker Cluster</a> &#8211; Avoid cluttered maps by using numbered markers at high zoom levels. Now with super fast server-side clustering!</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/ajax-duplicate-alert/" title="Listing already exists?" rel="nofollow ugc">Duplicate alert</a> &#8211; Send an alert to users when they add a submission with the same title as another to avoid spam listings.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/custom-google-maps/" title="Customize your maps look and feel" rel="nofollow ugc">Custom Map Styles</a> &#8211; Modify the look and feel of all Maps widgets via an intuitive user interface with color pickers and simple-to-use options.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/social-importer/" title="Import 1 listing at a time from Facebook, Yelp, Google My Business, and Trip Advisor!" rel="nofollow ugc">Migrate listings from other sites with Social Importer</a> &#8211; Import pages and events from Facebook and listings from Google My Business, Yelp, and Trip Advisor. One listing at a time, no bulk scraping.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/gd-recaptcha/" title="Stop spammers!" rel="nofollow ugc">Say Goodbye to spam listings with GD reCAPTCHA</a> &#8211; Banish spam by adding the No CAPTCHA reCAPTCHA widget to any GeoDirectory form.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/franchise-manager/" title="Franchise Manager" rel="nofollow ugc">Manage multiple business locations with Franchise Manager</a> &#8211; The faster, more innovative way to submit listings on directory pages for business chains or franchises.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/list-manager/" title="List Manager" rel="nofollow ugc">Create saveable lists with List Manager</a> &#8211; Give users the ability to create and save personal lists of businesses or events and make them public to other users for more productive searching.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/wp-all-import/" title="WP All Import" rel="nofollow ugc">WP All Import</a> &#8211; Use the power of WP All Import to import your listings from anywhere with this add-on that integrates Wp All Import with GeoDirectory</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/embeddable-ratings-badge/" title="Embeddable Ratings Badge" rel="nofollow ugc">Embeddable Ratings Badge</a> &#8211; Let users embed their listing info with current ratings on their site, styled the way they want.</p> </li> <li> <p><a href="https://wpgeodirectory.com/downloads/compare-listings/" title="Compare Listings" rel="nofollow ugc">Compare Listings</a> &#8211; Let your users compare listings side by side and compare vital info about the listings.</p> </li> </ul> <h3>⚡ GO PRO &#8211; BECOME A MEMBER!</h3> <p>Get on all the premium add-ons and themes and create an advanced Geo Directory. Sign up at <a href="https://wpgeodirectory.com/downloads/membership/" title="Get GeoDirectory membership." rel="nofollow ugc">wpgeodirectory.com</a>.</p> <h3>⚡ SUPPORT</h3> <p>You can get timely and friendly support for the Core Business Directory Plugin and add-ons at our <a href="https://wpgeodirectory.com/support" rel="nofollow ugc">official website</a>.</p> <h3>⚡ WHAT&#8217;S NEW IN GEODIRECTORY V2.0?</h3> <p>Your friends at AyeCode work to continuously refine the best directory plugins in the market to keep customers happy. Here&#8217;s what&#8217;s new in the newest version:<br /> * Extended Business Hours for listings<br /> * Tab builder, to design the tabs of your listings as you wish by drag and drop<br /> * Badge System, for &#8220;featured&#8221; listings, &#8220;new&#8221; listings, or to add whatever badge you want to your listings from any custom field.<br /> * Rating Styles using FontAwesome icons.<br /> * Custom Email Templates<br /> * Guest Frontend Add Listing<br /> * Improved SEO permalink settings.</p> <h3>⚡ CHECK OUT OUR DIRECTORY THEMES</h3> <ul> <li><a href="https://wpgeodirectory.com/downloads/directory-theme/" title="Directory Theme" rel="nofollow ugc">Directory Theme</a>. A free Theme to build Business, Events, and City Directories.</li> <li><a href="https://wpgeodirectory.com/downloads/real-estate-directory-theme/" title="Real Estate Theme" rel="nofollow ugc">Real Estate Theme</a>. A free Theme to build Real Estate directories. </li> <li><a href="https://wpgeodirectory.com/downloads/job-board-theme/" title="Job Board Theme" rel="nofollow ugc">Job Board Theme</a>. A free Theme to build Job Boards and Job Listings Directories. </li> </ul> <p>Our new Themes are built using our theme framework, Blocklstrap. The Blockstrap Theme combines the new WordPress Block Editor (FSE) with Bootstrap 5</p> <ul> <li>See all our <a href="https://wpgeodirectory.com/downloads/category/themes/" title="WordPress Directory Theme" rel="nofollow ugc">WordPress Directory Themes</a> and other templates.</li> </ul> <h3>⚡ AWESOME THEMES &amp; PAGE BUILDERS TUTORIALS</h3> <p>Our WordPress Directory Plugin works with any theme.</p> <p>See these tutorials to see how you can build:</p> <p>👉 <a href="https://wpgeodirectory.com/building-a-d
WordPress Plugin DirectoryWordPress Plugin Directory
2.38M