high · CVSS v3 7.5
CVE-2026-103913
The GeoDirectory plugin for WordPress is vulnerable to SQL injection via latitude/longitude coordinates. Attackers with Subscriber-level acc
Overview
The GeoDirectory plugin for WordPress is vulnerable to SQL injection via latitude/longitude coordinates. Attackers with Subscriber-level access can inject SQL when saving listings, potentially extracting sensitive data. This affects all versions up to 2.8.186.
Description
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post= and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Impact
Confidentiality: attackers can read arbitrary database tables. Integrity: potential data tampering. Availability: not directly impacted but could lead to resource exhaustion. Defenders: WordPress site owners and administrators.
Remediation
Upgrade GeoDirectory to 2.8.187 or later. If upgrade not possible, restrict wp_ajax_nopriv_geodir_widget_listings to authenticated users only, or disable the widget. Ensure input validation for latitude/longitude and use prepared statements.
Risk context
Severity high, CVSS 7.5. No EPSS data. Defenders should treat as high priority patch.
Affected products
- WordPress GeoDirectory plugin
- WordPress
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —