Skip to content
Threat Feed
high advisory

SQL Injection in GeoDirectory WordPress Plugin

The GeoDirectory WordPress plugin (<= 2.8.186) is vulnerable to SQL injection, allowing authenticated attackers to execute arbitrary database queries via improper coordinate sanitization in the geodir_gps_query_part function.

CVE search metadata

CVE search record: CVE-2026-103913. Severity: high. CVSS: 7.5. KEV: no. Product: GeoDirectory (<= 2.8.186). Brief: SQL Injection in GeoDirectory WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-geodirectory-sql-injection/

The GeoDirectory plugin for WordPress, in versions up to and including 2.8.186, contains a SQL injection vulnerability. The flaw originates from the geodir_gps_query_part() function, which fails to properly escape or validate latitude and longitude coordinate values before interpolating them into a database query string. This vulnerability is triggered when the application handles requests through the wp_ajax_nopriv_geodir_widget_listings handler. An attacker with Subscriber-level access can supply a malicious, crafted latitude or longitude coordinate during a listing update process. When the application subsequently processes a request with the sort_by=distance_asc parameter, the unvalidated coordinate input is executed as part of a SQL query. This allows attackers to manipulate database queries, potentially leading to unauthorized data exfiltration or sensitive information disclosure from the underlying WordPress database.

Impact

Successful exploitation of this vulnerability allows authenticated attackers with minimal privileges (Subscriber) to read sensitive data from the site database. This could include user credentials, personally identifiable information (PII), or other sensitive configuration data stored in the WordPress environment. The impact is significant for organizations relying on GeoDirectory for their business listings or directory services.

Recommendation

Update the GeoDirectory plugin to a patched version beyond 2.8.186 immediately. Ensure that all WordPress plugins are kept up to date and that administrative/subscriber privileges are strictly managed. Conduct a audit of database logs for unusual query patterns originating from the wp_ajax_nopriv_geodir_widget_listings handler.


Immediate actions

Deploy WAF rules to sanitize requests containing SQL keywords directed at the GeoDirectory AJAX endpoint.

SOC 24h

Mitigations

Update GeoDirectory plugin to version > 2.8.186.

immediate IT Operations

CVE-2026-103913

Detection coverage 1

Detect CVE-2026-103913 Exploitation - SQL Injection in GeoDirectory

high

Detects potential SQL injection attempts against the GeoDirectory plugin by monitoring for suspicious patterns in AJAX requests to the widget listings endpoint.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →