CVE-2026-15300 CRITICAL

CVE-2026-15300: GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters

Vendor Ninjew
Product GEO my WP
Weakness CWE-89 · SQLi
Published July 10, 2026
Last update July 10, 2026

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() before being interpolated into unquoted numeric positions in the proximity-search query (HAVING/SELECT clause distance math, BETWEEN bounding-box pre-filter) built by gmw_locations_query() in plugins/posts-locator/includes/class-gmw-wp-query.php. Because esc_sql() only escapes string delimiters and these positions are numeric, payloads such as `1 OR SLEEP(3)` survived sanitization. Fixed in 4.5.5 by adding an upstream is_numeric() guard that short-circuits the WHERE clause to `AND 1 = 0` when either coordinate is non-numeric, and by replacing the three esc_sql() calls with (float) casts.

Explanation of Vulnerability in Simple Terms

02Summary

GEO my WP versions 4.5.4 and earlier contain a SQL injection vulnerability in how the plugin processes database queries. An attacker can inject malicious SQL code through user input to modify or delete data in the site's database without authentication. This vulnerability affects data integrity and availability for all sites running the affected versions.

What an attacker can do

03Attacker Capabilities

Inject SQL commands to modify, delete, or exfiltrate data from the site database.

Potential impact on your site

04Site Impact

Database records can be altered or deleted, potentially causing data loss and site malfunction.

Conditions required to exploit

05Prerequisites

Network access to the site; no authentication or user interaction required.

Key dates

06Disclosure timeline

July 10, 2026 CVE published
July 10, 2026 Record updated

Related vulnerabilities

08Related CVE