SQL Injection Vulnerability in Geo Mashup Plugin for WordPress
CVE-2026-6457
6.5MEDIUM
What is CVE-2026-6457?
The Geo Mashup plugin for WordPress has a security flaw that allows authenticated attackers, including those with subscriber-level access, to exploit time-based blind SQL Injection vulnerabilities through the 'geo_mashup_null_fields' parameter. This arises from inadequate input escaping and insufficient query preparation on an existing SQL query. As a result, attackers can append malicious SQL queries, enabling them to extract sensitive information from the underlying database.
Affected Version(s)
Geo Mashup 0 <= 1.13.19