---
id: CVE-2026-16988
title: >-
  The GeoDirectory  WordPress plugin before 2.8.169 does not perform any
  authorization check when returning map marker data for a single requested
  listing, allowing unauthenticated users to disclose the title and exact
  geographic coordinat…
summary: >-
  The GeoDirectory  WordPress plugin before 2.8.169 does not perform any
  authorization check when returning map marker data for a single requested
  listing, allowing unauthenticated users to disclose the title and exact
  geographic coordinat…
severity: none
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16988'
references:
  - url: 'https://wpscan.com/vulnerability/162fa8ab-4d80-46f8-9a15-63c8dfd0be33/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00434
epssPercentile: 0.35078
ingestedAt: '2026-08-09T15:33:38.043Z'
---

## Overview

The GeoDirectory  WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthenticated users to disclose the title and exact geographic coordinates of non-public (pending or draft) listings.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
