rootpwn

high · CVSS v3 7.5

CVE-2026-103913

The GeoDirectory plugin for WordPress is vulnerable to SQL injection via latitude/longitude coordinates. Attackers with Subscriber-level acc

Overview

The GeoDirectory plugin for WordPress is vulnerable to SQL injection via latitude/longitude coordinates. Attackers with Subscriber-level access can inject SQL when saving listings, potentially extracting sensitive data. This affects all versions up to 2.8.186.

Description

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post= and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Impact

Confidentiality: attackers can read arbitrary database tables. Integrity: potential data tampering. Availability: not directly impacted but could lead to resource exhaustion. Defenders: WordPress site owners and administrators.

Remediation

Upgrade GeoDirectory to 2.8.187 or later. If upgrade not possible, restrict wp_ajax_nopriv_geodir_widget_listings to authenticated users only, or disable the widget. Ensure input validation for latitude/longitude and use prepared statements.

Risk context

Severity high, CVSS 7.5. No EPSS data. Defenders should treat as high priority patch.

Affected products

  • WordPress GeoDirectory plugin
  • WordPress

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
—
EPSS
—

SQL Injection WordPress GeoDirectory Privilege Escalation Data Exfiltration High Severity

← All CVEs