Junglewise Threat Intelligence

CVE-2026-39512: GeoDirectory SQL injection in WordPress plugin

CVE-2026-39512 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Executive brief

GeoDirectory is a WordPress plugin used to create global business directories. A security flaw allows unauthorized individuals to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer data, exposure of site configurations, or disruption of the directory service.

Technical details

A SQL injection vulnerability exists in the GeoDirectory plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to unauthenticated remote attackers over the network with low attack complexity. By sending specially crafted requests, an attacker can bypass security controls to execute arbitrary SQL queries against the database. This can result in high confidentiality impact through data exfiltration and limited availability impact. The vulnerability is addressed in version 2.8.154.

Affected products

  • GeoDirectory GeoDirectory <= 2.8.152

Timeline

  • 2026-02-19: other: Reported by researcher Tin Pham
  • 2026-04-13: disclosed: Initial disclosure by Patchstack
  • 2026-06-15: advisory: NVD publication date
  • 2026-04-13: patched: Patch released in version 2.8.154

References