CVE-2026-42671

WordPress GeoDirectory plugin <= 2.8.157 - Broken Access Control vulnerability

Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.


We have discovered 1,296 live websites that are affected by CVE-2026-42671.

Run a Free Instant Scan




Affected Software

Product  Geodirectory
Category Wordpress Plugins
Vulnerable Domains1,296 live websites (45% of Geodirectory install base)
Vulnerable Versions
  • from 0 through 2.8.157
Vulnerable Versions Count150 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 1, 2026
  • Updated - Jun 1, 2026

Credits

  • Evan NR | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-42671
United States577 websites



GB98 websites
Germany84 websites
Spain48 websites
France48 websites
Italy40 websites
Poland34 websites
Australia33 websites
South Africa33 websites
Canada33 websites

Website Distribution by TLD

Number of websites using CVE-2026-42671
.com596 websites
.org101 websites
.co.uk58 websites
.net48 websites
.de46 websites
.it32 websites
.com.au27 websites
.pl24 websites
.ca23 websites
.fr22 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-42671

Top websites that are affected by CVE-2026-42671. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**,***
****.org United States**,***
***************.com United States**,***
****************.com United States***,***
*********.com United States***,***
***********.com United States***,***
***********.eu Poland***,***
***********.com United States***,***
****.de Germany***,***
************.com United States***,***
See full domain list

FAQ

CVE-2026-42671 is Missing Authorization in Geodirectory
A total of 1,296 websites have been identified as vulnerable to CVE-2026-42671, based on global website indexing conducted by WebTechSurvey.
The Geodirectory is affected by the CVE-2026-42671 vulnerability.
Geodirectory versions up to and including 2.8.157 are vulnerable to CVE-2026-42671.