Unauthenticated SQL Injection in GeoDirectory Plugin by WordPress
CVE-2026-39512
9.3CRITICAL
What is CVE-2026-39512?
GeoDirectory versions 2.8.152 and prior are susceptible to unauthenticated SQL Injection vulnerabilities. This flaw allows attackers to execute arbitrary SQL queries within the application's database, potentially exposing sensitive data and compromising the integrity of the affected system. It is advisable for users to upgrade to the latest secure version of the plugin to mitigate risks associated with this vulnerability.
Affected Version(s)
GeoDirectory <= 2.8.152
References
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tin Pham aka TF1T | Patchstack Bug Bounty Program