CVE-2024-13507

GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.97 - Unauthenticated SQL Injection

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2.8.97 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 583 live websites that are affected by CVE-2024-13507.

Run a Free Instant Scan




Affected Software

Product  Geodirectory
Category Wordpress Plugins
Vulnerable Domains583 live websites (20% of Geodirectory install base)
Vulnerable Versions
  • from 0 through 2.8.97
Vulnerable Versions Count95 versions ( 59% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 26, 2025
  • Updated - Apr 8, 2026

Credits

  • Michael Mazzolini (finder)

Website Distribution by Country

Number of websites using CVE-2024-13507
United States240 websites



GB42 websites
Germany41 websites
Spain34 websites
Italy24 websites
France21 websites
Israel15 websites
Australia12 websites
Canada12 websites
South Africa12 websites

Website Distribution by TLD

Number of websites using CVE-2024-13507
.com271 websites
.org37 websites
.net33 websites
.co.uk24 websites
.de21 websites
.it18 websites
.es11 websites
.com.au9 websites
.fr8 websites
.pl8 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-13507

Top websites that are affected by CVE-2024-13507. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
***************.com United States**,***
****************.com United States***,***
***********.com United States***,***
************.com United States***,***
******************.com United States***,***
*******************.com United States***,***
**********************.***.uk GB***,***
******.edu United States***,***
********************.com United States***,***
See full domain list

FAQ

CVE-2024-13507 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Geodirectory
A total of 583 websites have been identified as vulnerable to CVE-2024-13507, based on global website indexing conducted by WebTechSurvey.
The Geodirectory is affected by the CVE-2024-13507 vulnerability.
Geodirectory versions up to and including 2.8.97 are vulnerable to CVE-2024-13507.