Geo My WP <= 4.5.5.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Geolocation Record Modification and Deletion
medium
The Geo My WP plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.5.5.2. This is due to missing ownership verification against the stored record when processing an existing location ID, allowing the submitted object_type and object_id to bypass the capability check...
- CVSS:
- 4.3
- Affected:
- up to 4.5.5.2
- Fixed in:
- 4.5.5.3
- Disclosed:
- Jul 24, 2026
CVE-2026-15260 on NVD →
GEO my WP <= 4.5.5 - Unauthenticated SQL Injection
high
The GEO my WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...
- CVSS:
- 7.5
- Affected:
- up to 4.5.5
- Fixed in:
- 4.5.5.1
- Disclosed:
- Jun 15, 2026
CVE-2026-52715 on NVD →
GEO my WP <= 4.5.5 - Unauthenticated SQL Injection via 'swlatlng' / 'nelatlng' Parameters
high
The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing WordPress's wp_magic_quotes protection, which only covers $_POST/$_GET/$_COOKIE/$_RE...
- CVSS:
- 7.5
- Affected:
- up to 4.5.5
- Fixed in:
- 4.5.5.1
- Disclosed:
- May 29, 2026
CVE-2026-9757 on NVD →
GEO my WP <= 4.5.4 - Unauthenticated SQL Injection
high
The GEO my WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into a...
- CVSS:
- 7.5
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.5
- Disclosed:
- May 28, 2026
GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters
critical
The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() be...
- CVSS:
- 9.1
- Affected:
- up to 4.5.4
- Fixed in:
- 4.5.5
- Disclosed:
- May 27, 2026
CVE-2026-15300 on NVD →
GEO my WP [geo-my-wp] < 4.5.1
unknown
[en] Missing Authorization vulnerability in Eyal Fitoussi GEO my WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GEO my WordPress: from n/a through 4.5.0.4.
- Affected:
- up to 4.5.1
- Fixed in:
- 4.5.1
- Disclosed:
- Dec 13, 2024
CVE-2024-54326 on NVD →
GEO my WordPress <= 4.5.0.4 - Missing Authorization via get_field_options_ajax
medium
The GEO my WordPress plugin for WordPress is vulnerable to unauthorized access to data due to a missing capability check on the get_field_options_ajax function in versions up to, and including, 4.5.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to obtain plugin settings...
- CVSS:
- 5.4
- Affected:
- up to 4.5.0.4
- Fixed in:
- 4.5.1
- Disclosed:
- Dec 11, 2024
CVE-2024-54326 on NVD →
GEO my WP [geo-my-wp] >= 4.0 - < 4.5
unknown
[en] The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
- Affected:
- 4.0 – 4.5
- Fixed in:
- 4.5
- Disclosed:
- Nov 22, 2024
CVE-2024-9422 on NVD →
GEO My WordPress <= 4.4.0.2 - Authenticated (Admin+) Arbitrary File Upload
high
The GEO My WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in versions up to, and including 4.4.0.2 (or version up to 3.1 for premium). This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on t...
- CVSS:
- 7.2
- Affected:
- 4.0 – 4.4.0.2
- Fixed in:
- 4.5
- Disclosed:
- Oct 31, 2024
CVE-2024-9422 on NVD →
GEO my WP [geo-my-wp] < 4.5.0.4
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eyal Fitoussi GEO my WordPress allows Reflected XSS.This issue affects GEO my WordPress: from n/a through 4.5.0.3.
- Affected:
- up to 4.5.0.4
- Fixed in:
- 4.5.0.4
- Disclosed:
- Oct 6, 2024
CVE-2024-47327 on NVD →
GEO my WordPress <= 4.5.0.3 - Reflected Cross-Site Scripting
medium
The GEO my WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.5.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfu...
- CVSS:
- 6.1
- Affected:
- up to 4.5.0.3
- Fixed in:
- 4.5.0.4
- Disclosed:
- Sep 25, 2024
CVE-2024-47327 on NVD →
GEO my WP [geo-my-wp] < 4.5.0.2
unknown
[en] The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.
- Affected:
- up to 4.5.0.2
- Fixed in:
- 4.5.0.2
- Disclosed:
- Aug 19, 2024
CVE-2024-6330 on NVD →
GEO my WordPress <= 4.5.0.1 - Unauthenticated Local File Inclusion
critical
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.0.1 via the 'form[info_window_template][content_path]' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PH...
- CVSS:
- 9.8
- Affected:
- up to 4.5.0.1
- Fixed in:
- 4.5.0.2
- Disclosed:
- Jul 29, 2024
CVE-2024-6330 on NVD →
GEO my WP [geo-my-wp] < 4.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.1.
- Affected:
- up to 4.2
- Fixed in:
- 4.2
- Disclosed:
- Apr 15, 2024
CVE-2024-32097 on NVD →
GEO my WordPress <= 4.1 - Cross-Site Request Forgery
medium
The GEO my WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can tric...
- CVSS:
- 4.3
- Affected:
- up to 4.1
- Fixed in:
- 4.2
- Disclosed:
- Apr 11, 2024
CVE-2024-32097 on NVD →
GEO my WP [geo-my-wp] < 4.0.3
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2.
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Dec 31, 2023
CVE-2023-52134 on NVD →
GEO my WordPress <= 4.0.2 - Authenticated(Administrator+) SQL Injection
medium
The GEO my WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.0.3 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator access and ab...
- CVSS:
- 6.6
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.3
- Disclosed:
- Dec 28, 2023
CVE-2023-52134 on NVD →
GEO my WP [geo-my-wp] < 4.0.1
unknown
[en] The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above per...
- Affected:
- up to 4.0.1
- Fixed in:
- 4.0.1
- Disclosed:
- Oct 10, 2023
CVE-2023-5467 on NVD →
GEO my WordPress <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissi...
- CVSS:
- 6.4
- Affected:
- up to 4.0
- Fixed in:
- 4.0.1
- Disclosed:
- Oct 9, 2023
CVE-2023-5467 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database