Description
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post=<pending-listing-id> and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-10-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection enabling data exfiltration
Action: Patch Now
AI Analysis

Impact

The GeoDirectory plugin accepts latitude and longitude values for a listing, stores them without numeric validation, and later interpolates those values directly into a distance calculation query. Because the query is executed by the public wp_ajax_nopriv_geodir_widget_listings handler when an attacker supplies a pending‑listing ID and requests sorting by distance, an authenticated user with Subscriber level or higher can inject additional SQL code. This injection (CWE‑89) allows the attacker to read arbitrary database tables and exfiltrate sensitive information such as user accounts or site configuration, potentially leading to a breach of confidentiality and data loss.

Affected Systems

All installations of the paoltaia:GeoDirectory WordPress plugin version 2.8.186 and earlier are vulnerable. The issue is present in the core plugin files and is not limited to a specific feature module. Users of any WordPress site running a patched or newer version of GeoDirectory are not affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating a high severity with moderate to high impact. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting that active exploitation has not been reported at the time of this analysis. Attackers must authenticate as a Subscriber or higher and must target the publicly accessible wp_ajax_nopriv_geodir_widget_listings endpoint while submitting set_post=<pending‑listing‑id> and sort_by=distance_asc. Once the injection succeeds, an attacker can execute arbitrary SELECT queries to retrieve sensitive data from the database.

Generated by OpenCVE AI on October 3, 2026 at 06:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest GeoDirectory plugin update (2.8.187 or newer).
  • Restrict or block access to the wp_ajax_nopriv_geodir_widget_listings AJAX endpoint for unauthenticated users or enforce role checks to allow only privileged users.
  • Disable pending listings or require administrative review before listings appear on the site to eliminate the attack vector.

Generated by OpenCVE AI on October 3, 2026 at 06:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post=<pending-listing-id> and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title GeoDirectory <= 2.8.186 - Unauthenticated SQL Injection via 'latitude' Parameter via Stored Pending Listing
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:45.332Z

Reserved: 2026-10-01T14:17:33.772Z

Link: CVE-2026-103913

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:27.169Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:41.800

Modified: 2026-10-03T16:16:34.333

Link: CVE-2026-103913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')