Impact
The Location Manager plugin for WordPress is vulnerable to generic SQL Injection through the latitude and longitude REST API parameters in all releases up to and including 2.3.38. Insufficient escaping and lack of prepared statements allow an unauthenticated attacker to inject arbitrary SQL when the orderby=lat_lon parameter is supplied, enabling the execution of additional queries and the extraction of sensitive database contents. This flaw is a classic example of CWE-89, compromising confidentiality.
Affected Systems
The vulnerable component is the AyeCode Ltd Location Manager plugin for WordPress. Every release from the initial launch up through version 2.3.38 is affected. The flaw is triggered on publicly accessible REST endpoints such as geodir/v2/locations/cities, /regions, /countries, and /neighbourhoods via the get_locations() and get_neighbourhoods() functions when the orderby=lat_lon parameter is used.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact on confidentiality, with the attack vector being remote and requiring no authentication. The EPSS score is under 1 percent, showing that widespread exploitation is presently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Because authentication is not required, any visitor to the WordPress site can craft a malicious request to the vulnerable REST endpoint and inject SQL, potentially exposing database contents. The risk remains significant for sites that expose these endpoints publicly, especially if the REST API is not restricted to authenticated users.
OpenCVE Enrichment