PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103913 paoltaia CVE debrief

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. Authenticated attackers with Subscriber-level access and above can append additional SQL queries to extract sensitive information from the database. This vulnerability allows for potential extraction of sensitive information and possible disruption of database integrity. Defenders should prioritize verifying exposure of GeoDirectory plugin versions up to 2.8.186 and assess the integrity of their database.

Vendor
paoltaia
Product
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

Defenders responsible for WordPress installations with the GeoDirectory plugin should assess exposure and verify the integrity of their database. This vulnerability allows authenticated attackers with Subscriber-level access and above to append additional SQL queries to extract sensitive information from the database.

Why it matters

CVE-2026-103913 is a SQL Injection vulnerability in the GeoDirectory plugin for WordPress that allows authenticated attackers to extract sensitive information from the database. Defenders should prioritize verifying exposure and assessing database integrity.

  • Potential extraction of sensitive information from the database
  • Possible disruption of database integrity
  • Need for verification of GeoDirectory plugin versions and database integrity
  • Requirement for monitoring suspicious database activity

Technical summary

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler.

Defensive priority

Defenders should prioritize verifying exposure of GeoDirectory plugin versions up to 2.8.186 and assess the integrity of their database.

Recommended defensive actions

  • Verify exposure of GeoDirectory plugin versions up to 2.8.186
  • Assess the integrity of the database
  • Restrict access to sensitive database information
  • Monitor for suspicious database activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the SQL Injection vulnerability in the GeoDirectory plugin. However, the corpus does not establish versions beyond 2.8.186, exploitation, impact, or remediation, which require verification from official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103913 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103913

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103913 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103913

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/class-geodir-ajax.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/class-geodir-post-data.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/general-functions.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.185/includes/widgets/class-geodir-widget-listings.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.