CVE-2026-15300: GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $SERVER['QUERYSTRING'] via parsestr() (bypassing wpmagicquotes, which does not cover $SERVER), then passed through bare escsql() before being interpolated into unquoted numeric positions in the proximity-search query (HAVING/SELECT clause distance math, BETWEEN bounding-box pre-filter) built by gmwlocationsquery() in plugins/posts-locator/includes/class-gmw-wp-query.php. Because escsql() only escapes string delimiters and these positions are numeric, payloads such as 1 OR SLEEP(3) survived sanitization. Fixed in 4.5.5 by adding an upstream isnumeric() guard that short-circuits the WHERE clause to AND 1 = 0 when either coordinate is non-numeric, and by replacing the three escsql() calls with (float) casts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GEO my WP plugin for WordPressto a version that resolves this vulnerability.Fixed in 4.5.5 - Configuration
Implement the upstream fix in class-gmw-wp-query.php: add an is_numeric() guard for the distance/lat/lng inputs so that when either coordinate is non-numeric the query uses short-circuit `AND 1 = 0`, and replace the three esc_sql() calls with `(float)` casts before interpolating into numeric SQL positions.
GEO my WP plugin for WordPress (plugins/posts-locator/includes/class-gmw-wp-query.php) SQL injection guard for distance/lat/lng = If either coordinate is non-numeric, short-circuit WHERE clause to AND 1 = 0; replace three esc_sql() calls with (float) casts
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15300?
CVE-2026-15300 has a severity rating of critical with a score of 9.1.
How do I fix CVE-2026-15300?
To fix CVE-2026-15300, update the GEO my WP plugin to version 4.5.5 or later.
What type of vulnerability is CVE-2026-15300?
CVE-2026-15300 is classified as an SQL Injection vulnerability.
Which parameters are affected by CVE-2026-15300?
CVE-2026-15300 affects the 'distance', 'lat', and 'lng' parameters in the GEO my WP plugin.
What is the impact of CVE-2026-15300?
CVE-2026-15300 can allow unauthenticated attackers to perform SQL Injection, potentially compromising the database.