plugin

Geo My Wp Vulnerabilities

19 known security issues reported for the Geo My Wp WordPress plugin. Most recent disclosed Jul 24, 2026.

2 critical 4 high 6 medium

Running Geo My Wp on your site? Check whether your installed version is affected.

Scan your site free

Geo My WP <= 4.5.5.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Geolocation Record Modification and Deletion

medium

The Geo My WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.5.5.2. This is due to missing ownership verification against the stored record when processing an existing location ID, allowing the submitted object_type and object_id to bypass the capability check...

CVSS:
4.3
Affected:
up to 4.5.5.2
Fixed in:
4.5.5.3
Disclosed:
Jul 24, 2026

CVE-2026-15260 on NVD →

GEO my WP <= 4.5.5 - Unauthenticated SQL Injection

high

The GEO my WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...

CVSS:
7.5
Affected:
up to 4.5.5
Fixed in:
4.5.5.1
Disclosed:
Jun 15, 2026

CVE-2026-52715 on NVD →

GEO my WP <= 4.5.5 - Unauthenticated SQL Injection via 'swlatlng' / 'nelatlng' Parameters

high

The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, which only covers $_POST/$_GET/$_COOKIE/$_RE...

CVSS:
7.5
Affected:
up to 4.5.5
Fixed in:
4.5.5.1
Disclosed:
May 29, 2026

CVE-2026-9757 on NVD →

GEO my WP <= 4.5.4 - Unauthenticated SQL Injection

high

The GEO my WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...

CVSS:
7.5
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
May 28, 2026

GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters

critical

The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() be...

CVSS:
9.1
Affected:
up to 4.5.4
Fixed in:
4.5.5
Disclosed:
May 27, 2026

CVE-2026-15300 on NVD →

GEO my WP [geo-my-wp] < 4.5.1

unknown

[en] Missing Authorization vulnerability in Eyal Fitoussi GEO my WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GEO my WordPress: from n/a through 4.5.0.4.

Affected:
up to 4.5.1
Fixed in:
4.5.1
Disclosed:
Dec 13, 2024

CVE-2024-54326 on NVD →

GEO my WordPress <= 4.5.0.4 - Missing Authorization via get_field_options_ajax

medium

The GEO my WordPress plugin for WordPress is vulnerable to unauthorized access to data due to a missing capability check on the get_field_options_ajax function in versions up to, and including, 4.5.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to obtain plugin settings...

CVSS:
5.4
Affected:
up to 4.5.0.4
Fixed in:
4.5.1
Disclosed:
Dec 11, 2024

CVE-2024-54326 on NVD →

GEO my WP [geo-my-wp] >= 4.0 - < 4.5

unknown

[en] The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

Affected:
4.0 – 4.5
Fixed in:
4.5
Disclosed:
Nov 22, 2024

CVE-2024-9422 on NVD →

GEO My WordPress <= 4.4.0.2 - Authenticated (Admin+) Arbitrary File Upload

high

The GEO My WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including 4.4.0.2 (or version up to 3.1 for premium). This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on t...

CVSS:
7.2
Affected:
4.0 – 4.4.0.2
Fixed in:
4.5
Disclosed:
Oct 31, 2024

CVE-2024-9422 on NVD →

GEO my WP [geo-my-wp] < 4.5.0.4

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eyal Fitoussi GEO my WordPress allows Reflected XSS.This issue affects GEO my WordPress: from n/a through 4.5.0.3.

Affected:
up to 4.5.0.4
Fixed in:
4.5.0.4
Disclosed:
Oct 6, 2024

CVE-2024-47327 on NVD →

GEO my WordPress <= 4.5.0.3 - Reflected Cross-Site Scripting

medium

The GEO my WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...

CVSS:
6.1
Affected:
up to 4.5.0.3
Fixed in:
4.5.0.4
Disclosed:
Sep 25, 2024

CVE-2024-47327 on NVD →

GEO my WP [geo-my-wp] < 4.5.0.2

unknown

[en] The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.

Affected:
up to 4.5.0.2
Fixed in:
4.5.0.2
Disclosed:
Aug 19, 2024

CVE-2024-6330 on NVD →

GEO my WordPress <= 4.5.0.1 - Unauthenticated Local File Inclusion

critical

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.0.1 via the 'form[info_window_template][content_path]' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PH...

CVSS:
9.8
Affected:
up to 4.5.0.1
Fixed in:
4.5.0.2
Disclosed:
Jul 29, 2024

CVE-2024-6330 on NVD →

GEO my WP [geo-my-wp] < 4.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.1.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Apr 15, 2024

CVE-2024-32097 on NVD →

GEO my WordPress <= 4.1 - Cross-Site Request Forgery

medium

The GEO my WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can tric...

CVSS:
4.3
Affected:
up to 4.1
Fixed in:
4.2
Disclosed:
Apr 11, 2024

CVE-2024-32097 on NVD →

GEO my WP [geo-my-wp] < 4.0.3

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2.

Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Dec 31, 2023

CVE-2023-52134 on NVD →

GEO my WordPress <= 4.0.2 - Authenticated(Administrator+) SQL Injection

medium

The GEO my WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.0.3 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator access and ab...

CVSS:
6.6
Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Dec 28, 2023

CVE-2023-52134 on NVD →

GEO my WP [geo-my-wp] < 4.0.1

unknown

[en] The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above per...

Affected:
up to 4.0.1
Fixed in:
4.0.1
Disclosed:
Oct 10, 2023

CVE-2023-5467 on NVD →

GEO my WordPress <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissi...

CVSS:
6.4
Affected:
up to 4.0
Fixed in:
4.0.1
Disclosed:
Oct 9, 2023

CVE-2023-5467 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database