SQL Injection Vulnerability in GeoDirectory Plugin for WordPress
CVE-2026-103913
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-103913?
The GeoDirectory plugin for WordPress is affected by a security flaw that allows SQL Injection through the improper handling of latitude and longitude coordinates. When listings are saved, the absence of adequate escaping and numeric validation allows authenticated attackers with Subscriber-level access or higher to conduct malicious SQL queries. This vulnerability can lead attackers to extract sensitive information from the database by injecting additional SQL statements into existing queries executed during the plugin's distance sorting functionality.
Affected Version(s)
GeoDirectory β WP Business Directory Plugin and Classified Listings Directory 0 <= 2.8.186