{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/geodirectory--2.8.186/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:geodirectory:geodirectory:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-103913"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GeoDirectory (\u003c= 2.8.186)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sql-injection","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe GeoDirectory plugin for WordPress, in versions up to and including 2.8.186, contains a SQL injection vulnerability. The flaw originates from the geodir_gps_query_part() function, which fails to properly escape or validate latitude and longitude coordinate values before interpolating them into a database query string. This vulnerability is triggered when the application handles requests through the wp_ajax_nopriv_geodir_widget_listings handler. An attacker with Subscriber-level access can supply a malicious, crafted latitude or longitude coordinate during a listing update process. When the application subsequently processes a request with the sort_by=distance_asc parameter, the unvalidated coordinate input is executed as part of a SQL query. This allows attackers to manipulate database queries, potentially leading to unauthorized data exfiltration or sensitive information disclosure from the underlying WordPress database.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows authenticated attackers with minimal privileges (Subscriber) to read sensitive data from the site database. This could include user credentials, personally identifiable information (PII), or other sensitive configuration data stored in the WordPress environment. The impact is significant for organizations relying on GeoDirectory for their business listings or directory services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the GeoDirectory plugin to a patched version beyond 2.8.186 immediately. Ensure that all WordPress plugins are kept up to date and that administrative/subscriber privileges are strictly managed. Conduct a audit of database logs for unusual query patterns originating from the wp_ajax_nopriv_geodir_widget_listings handler.\u003c/p\u003e\n","date_modified":"2026-10-03T06:54:04Z","date_published":"2026-10-03T06:54:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-geodirectory-sql-injection/","summary":"The GeoDirectory WordPress plugin (\u003c= 2.8.186) is vulnerable to SQL injection, allowing authenticated attackers to execute arbitrary database queries via improper coordinate sanitization in the geodir_gps_query_part function.","title":"SQL Injection in GeoDirectory WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-geodirectory-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - GeoDirectory (\u003c= 2.8.186)","version":"https://jsonfeed.org/version/1.1"}