Junglewise Threat Intelligence

CVE-2026-52715: GEO my WordPress unauthenticated SQL injection

CVE-2026-52715 · Severity: critical · CVSS 9.3 · Published 2026-06-16

Executive brief

GEO my WordPress is a popular WordPress plugin used to add location-based features and maps to websites. A critical security flaw allows unauthorized attackers to interact directly with the website's database without needing a password. This could lead to the theft of sensitive customer data, exposure of site configurations, or disruption of website operations.

Technical details

A SQL injection vulnerability exists in the GEO my WordPress plugin for WordPress due to improper neutralization of special elements in SQL commands (CWE-89). The flaw is present in versions up to and including 4.5.5. Because the vulnerability is unauthenticated and reachable over the network, a remote attacker can exploit it without any prior access or user interaction. Successful exploitation allows for unauthorized data extraction from the database and potential impact on data integrity. The issue has been addressed in version 4.5.5.1.

Affected products

  • GEO my WordPress GEO my WordPress <= 4.5.5

Timeline

  • 2026-04-10: other: Reported by researcher alvarodh5
  • 2026-06-15: advisory: Patchstack advisory published
  • 2026-06-16: disclosed: CVE published to NVD dataset

References