Skip to main content
QUIETLYTIC
Vulnerability

GeoDirectory SQL Injection (CVE-2026-84813)

CVE-2026-84813 is a CVSS 9.3 unauthenticated SQL injection flaw in the GeoDirectory WordPress plugin, reported exploited by VulnCheck KEV.

CVE-2026-84813
Threat Level
CRITICAL
CVSS
9.3
Status
Active Exploitation
Confidence
Medium
Affected Products
GeoDirectory, GeoDirectory (through 2.8.174)

CVE-2026-84813 carries a CVSS 3.1 base score of 9.3 against GeoDirectory, a WordPress plugin published by AyeCode for building business directory and listing sites. NVD classifies it as CWE-89 (SQL Injection) and states the affected range as versions up to and including 2.8.174. VulnCheck’s KEV feed reports the CVE as exploited, dated September 2, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-84813 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s own summary is brief: unauthenticated SQL injection in GeoDirectory versions up to and including 2.8.174. Patchstack’s vulnerability database, cited directly from NVD’s reference list, tracks this CVE under the same CWE-89 classification. The CVSS vector’s Scope-Changed (S:C) component alongside C:H/I:N/A:L indicates a confidentiality-focused, likely blind or data-extraction-oriented injection rather than one that also grants broad write or availability impact — consistent with a query-parameter or search-field injection pattern common to WordPress directory and listing plugins, though NVD’s summary does not name the specific vulnerable parameter or endpoint.

We report NVD’s classification and affected-version boundary as stated rather than speculating about the missing endpoint-level detail.

Evidence and confidence

  • Medium confidence — the CVSS 9.3 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L), the CWE-89 classification, and the affected-version ceiling (2.8.174) all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Below-midpoint exploitation probability — FIRST’s EPSS model scores this CVE at 0.00236, a 15.0th percentile score as of our ingestion — one of the lower scores in our recent coverage despite the confirmed exploitation report.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD’s summary states only the affected ceiling.

Why this matters

GeoDirectory is used to power business-directory and listing sites, which typically store business contact information, reviews, and sometimes user account data reachable through the same database an unauthenticated SQL injection can query. The vulnerability’s requirement of no authentication and no user interaction (PR:N, UI:N) means it’s reachable by any visitor to an affected site, and the below-midpoint EPSS score should not be read as reducing the urgency the confirmed exploitation report and CVSS 9.3 score together already establish.

Because NVD’s summary doesn’t specify the vulnerable parameter, site operators cannot narrow their exposure through configuration and should treat the version boundary as the operative signal: any site running 2.8.174 or earlier should be upgraded.

Frequently Asked Questions

What is CVE-2026-84813? A CVSS 9.3 unauthenticated SQL injection vulnerability (CWE-89) in the GeoDirectory WordPress plugin, affecting versions up to and including 2.8.174.

Is CVE-2026-84813 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 2, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states versions through 2.8.174 are affected; confirm directly with AyeCode’s changelog whether a later release addresses this specific CVE.


Severity, vector, weakness classification, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-84813, which cites Patchstack’s vulnerability database entry. Exploitation status and the September 2, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools