Unauthenticated SQL Injection in GEO my WordPress Plugin by GEO my WP
CVE-2026-52715

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 June 2026

What is CVE-2026-52715?

An unauthenticated SQL injection vulnerability exists in the GEO my WordPress plugin prior to version 4.5.5. This vulnerability can be exploited by sending crafted requests that manipulate SQL queries, potentially allowing an attacker to retrieve sensitive data from the database. It is crucial for users of affected versions to apply available patches and updates to secure their installations.

Affected Version(s)

GEO my WordPress <= 4.5.5

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

alvarodh5 | Patchstack Bug Bounty Program
.