Unauthenticated SQL Injection in GeoDirectory Plugin by WordPress
CVE-2026-39512

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-39512?

GeoDirectory versions 2.8.152 and prior are susceptible to unauthenticated SQL Injection vulnerabilities. This flaw allows attackers to execute arbitrary SQL queries within the application's database, potentially exposing sensitive data and compromising the integrity of the affected system. It is advisable for users to upgrade to the latest secure version of the plugin to mitigate risks associated with this vulnerability.

Affected Version(s)

GeoDirectory <= 2.8.152

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tin Pham aka TF1T | Patchstack Bug Bounty Program
.