← Späť na vyhľadávanie CVE

CVE-2026-15300

GEO my WP

Popis

The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the -distance-, -lat-, and -lng- parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER[-QUERY_STRING-] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() before being interpolated into unquoted numeric positions in the proximity-search query (HAVING/SELECT clause distance math, BETWEEN bounding-box pre-filter) built by gmw_locations_query() in plugins/posts-locator/includes/class-gmw-wp-query.php. Because esc_sql() only escapes string delimiters and these positions are numeric, payloads such as `1 OR SLEEP(3)` survived sanitization. Fixed in 4.5.5 by adding an upstream is_numeric() guard that short-circuits the WHERE clause to `AND 1 = 0` when either coordinate is non-numeric, and by replacing the three esc_sql() calls with (float) casts.

CVSS 9.1EPSS 0.349%Riziko 0.94
Zobraziť zdroj
Zverejnené
2026-07-10 05:16:33
Dotknuté verzie
<=4.5.4
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H