CPE
The GeoDirectory WordPress plugin (<= 2.8.186) is vulnerable to SQL injection, allowing authenticated attackers to execute arbitrary database queries via improper coordinate sanitization in the geodir_gps_query_part function.