PatchSiren cyber security CVE debrief
CVE-2026-103913 paoltaia CVE debrief
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. Authenticated attackers with Subscriber-level access and above can append additional SQL queries to extract sensitive information from the database. This vulnerability allows for potential extraction of sensitive information and possible disruption of database integrity. Defenders should prioritize verifying exposure of GeoDirectory plugin versions up to 2.8.186 and assess the integrity of their database.
- Vendor
- paoltaia
- Product
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-03
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-03
- Advisory updated
- 2026-10-03
Who should care
Defenders responsible for WordPress installations with the GeoDirectory plugin should assess exposure and verify the integrity of their database. This vulnerability allows authenticated attackers with Subscriber-level access and above to append additional SQL queries to extract sensitive information from the database.
Why it matters
CVE-2026-103913 is a SQL Injection vulnerability in the GeoDirectory plugin for WordPress that allows authenticated attackers to extract sensitive information from the database. Defenders should prioritize verifying exposure and assessing database integrity.
- Potential extraction of sensitive information from the database
- Possible disruption of database integrity
- Need for verification of GeoDirectory plugin versions and database integrity
- Requirement for monitoring suspicious database activity
Technical summary
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler.
Defensive priority
Defenders should prioritize verifying exposure of GeoDirectory plugin versions up to 2.8.186 and assess the integrity of their database.
Recommended defensive actions
- Verify exposure of GeoDirectory plugin versions up to 2.8.186
- Assess the integrity of the database
- Restrict access to sensitive database information
- Monitor for suspicious database activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the SQL Injection vulnerability in the GeoDirectory plugin. However, the corpus does not establish versions beyond 2.8.186, exploitation, impact, or remediation, which require verification from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-103913 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-103913
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-103913 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103913
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/class-geodir-ajax.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/class-geodir-post-data.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/general-functions.php
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/widgets/class-geodir-widget-listings.php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.