Unauthenticated SQL Injection in GEO my WordPress Plugin by GEO my WP
CVE-2026-52715
9.3CRITICAL
What is CVE-2026-52715?
An unauthenticated SQL injection vulnerability exists in the GEO my WordPress plugin prior to version 4.5.5. This vulnerability can be exploited by sending crafted requests that manipulate SQL queries, potentially allowing an attacker to retrieve sensitive data from the database. It is crucial for users of affected versions to apply available patches and updates to secure their installations.
Affected Version(s)
GEO my WordPress <= 4.5.5