Executive brief
GEO my WP is a WordPress plugin used to add location-based search and mapping features to websites. A security flaw allows unauthenticated visitors to perform unauthorized database queries by manipulating specific web address parameters. This could lead to the theft of sensitive information, such as user data or site configuration details, from the website's database.
Technical details
The GEO my WP plugin for WordPress is vulnerable to SQL injection due to improper handling of the 'swlatlng' and 'nelatlng' parameters in the gmw_get_locations_within_boundaries_sql() function. These parameters are parsed directly from the query string using parse_str(), which bypasses WordPress's built-in magic quotes protection. The values are then exploded and interpolated into a SQL BETWEEN clause without being cast to floats, validated as numeric, or passed through $wpdb->prepare(). An unauthenticated attacker can exploit this by sending crafted requests to a page containing the Posts Locator search-results shortcode, provided at least one post has associated location data. This allows for the extraction of sensitive data via boolean-based or time-based blind SQL injection.
Affected products
- GEO my WP GEO my WP Up to and including 4.5.5
Timeline
- 2026-05-30: advisory: CVE-2026-9757 published
References
- https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5/includes/class-gmw-form-core.php
- https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5/includes/class-gmw-form.php
- https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5/includes/gmw-functions.php
- https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5/includes/gmw-functions.php
- https://plugins.trac.wordpress.org/browser/geo-my-wp/tags/4.5.5/plugins/posts-locator/includes/class-gmw-wp-query.php
- https://plugins.trac.wordpress.org/changeset/3552886/geo-my-wp/trunk/includes/gmw-functions.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fgeo-my-wp/tags/4.5.5&new_path=%2Fgeo-my-wp/tags/4.5.5.1