Vendor
high
advisory
Unauthenticated SQL Injection in GEO my WordPress Plugin
1 rule 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2026-52715) in the GEO my WordPress plugin allows attackers to exfiltrate database contents via malicious query parameters.
GEO my WordPress
1r
1t
1c
critical
advisory
CVE-2026-15300: Critical SQL Injection in GEO my WP WordPress Plugin
1 rule 2 TTPs 1 CVEA critical SQL Injection vulnerability, identified as CVE-2026-15300, was found in the GEO my WP plugin for WordPress, affecting versions up to and including 4.5.4, allowing attackers to inject SQL payloads through the 'distance', 'lat', and 'lng' parameters, leading to potential data compromise or denial of service.
GEO my WP plugin <= 4.5.4
wordpress
plugin
sql-injection
vulnerability
webserver
1r
2t
1c