{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3alocation_manager_projectlocation_managerwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:location_manager_project:location_manager:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85705"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Location Manager (\u003c= 2.3.38)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sql-injection","wordpress"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Location Manager plugin for WordPress is vulnerable to generic SQL injection in all versions up to and including 2.3.38. The vulnerability exists due to insufficient escaping of user-supplied input and a lack of prepared statements in the plugin's SQL query construction. Attackers can exploit this flaw by sending specifically crafted HTTP requests to the REST API.\u003c/p\u003e\n\u003cp\u003eWhen the 'orderby=lat_lon' parameter is combined with manipulated 'latitude' or 'longitude' parameters, the underlying database queries in the get_locations() and get_neighbourhoods() functions are improperly sanitized. This allows unauthenticated remote attackers to append malicious SQL commands to legitimate queries. Exploitation can result in unauthorized access to and exfiltration of sensitive information contained within the WordPress database. Affected endpoints include /geodir/v2/locations/cities, /regions, /countries, and /neighbourhoods.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform blind or error-based SQL injection, potentially leading to full database compromise or the extraction of sensitive site data, user credentials, or configuration details.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Location Manager plugin to the latest version (v2.3.39 or higher) immediately to resolve the lack of input sanitization.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block incoming HTTP requests to REST API endpoints containing 'orderby=lat_lon' that also include SQL keywords or syntax (e.g., SELECT, UNION, SLEEP) in the latitude/longitude parameters.\u003c/li\u003e\n\u003cli\u003eReview database access logs for unusual query patterns or unexpected error messages originating from the plugin's REST API endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T10:05:29Z","date_published":"2026-09-18T10:05:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85705/","summary":"The Location Manager plugin for WordPress is vulnerable to unauthenticated SQL injection via REST API parameters, allowing remote attackers to extract sensitive database information.","title":"SQL Injection in Location Manager Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85705/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:location_manager_project:location_manager:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}