{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/geo-my-wordpress--4.5.5.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.3,"id":"CVE-2026-52715"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GEO my WordPress (\u003c 4.5.5.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GEO my WP"],"content_html":"\u003cp\u003eCVE-2026-52715 is a high-severity unauthenticated SQL injection vulnerability affecting the GEO my WordPress plugin versions prior to 4.5.5.1. The flaw exists due to improper handling of user-supplied query parameters, specifically 'swlatlng' and 'nelatlng', which are passed through the 'parse_str' function and subsequently interpolated into a SQL 'BETWEEN' clause within the 'gmw_get_locations_within_boundaries_sql' function. An attacker can exploit this via crafted GET requests to perform blind time-based or boolean-based SQL injection, potentially leading to the full exfiltration of the WordPress database, including user credentials. A public proof-of-concept exploit was released on August 14, 2026, significantly increasing the risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a public-facing WordPress page utilizing the GEO my WordPress shortcode [gmw form=\u0026quot;1\u0026quot;].\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP GET request targeting the page, appending or modifying query parameters 'swlatlng' or 'nelatlng'.\u003c/li\u003e\n\u003cli\u003eThe plugin's 'GMW_Form::set_default_values' method processes the 'QUERY_STRING' and passes it to 'gmw_get_form_values'.\u003c/li\u003e\n\u003cli\u003eThe 'gmw_get_form_values' function uses 'parse_str' on the input without an allowlist, allowing the malicious 'swlatlng' or 'nelatlng' parameters to persist.\u003c/li\u003e\n\u003cli\u003eThe 'parse_query_args' function copies these parameters into the search arguments used by the database query builder.\u003c/li\u003e\n\u003cli\u003eThe 'gmw_get_locations_within_boundaries_sql' function performs direct string interpolation of the tainted input into a SQL 'BETWEEN' clause.\u003c/li\u003e\n\u003cli\u003eThe 'WP_Query' object executes the resulting 'get_results' call, triggering the injection against the MariaDB backend.\u003c/li\u003e\n\u003cli\u003eThe attacker observes application response times (time-based) or changes in the 'total_results' JSON field (boolean-based) to exfiltrate database records.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated attackers to read sensitive database records. Successful exploitation can lead to full compromise of the WordPress site, including the exfiltration of user account information, administrative hashes, and other sensitive site configuration data. The vulnerability is rated CVSS 9.3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the GEO my WordPress plugin to version 4.5.5.1 or higher to incorporate the patch.\u003c/li\u003e\n\u003cli\u003eDeploy a WAF rule to inspect incoming HTTP GET requests for non-numeric, suspicious characters in the 'swlatlng' and 'nelatlng' query parameters.\u003c/li\u003e\n\u003cli\u003eReview web server logs for request patterns containing 'swlatlng=' or 'nelatlng=' followed by SQL syntax (e.g., 'SLEEP', 'CASE', 'WHEN', 'THEN').\u003c/li\u003e\n\u003cli\u003eIf compromise is suspected, initiate incident response procedures, rotate administrative credentials, and audit database user activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T21:22:19Z","date_published":"2026-08-14T21:22:19Z","id":"https://feed.craftedsignal.io/briefs/2026-08-geowp-sqli/","summary":"An unauthenticated SQL injection vulnerability (CVE-2026-52715) in the GEO my WordPress plugin allows attackers to exfiltrate database contents via malicious query parameters.","title":"Unauthenticated SQL Injection in GEO my WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-geowp-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - GEO My WordPress (\u003c 4.5.5.1)","version":"https://jsonfeed.org/version/1.1"}