CVE-2026-15300 | ninjew GEO my WP Plugin up to 4.5.4 on WordPress Proximity-Search Query class-gmw-wp-query.php gmw_locations_query distance/lat/lng sql injection

SecurityVulns

A vulnerability described as critical has been identified in ninjew GEO my WP Plugin up to 4.5.4 on WordPress. This affects the function gmw_locations_query of the file plugins/posts-locator/includes/class-gmw-wp-query.php of the component Proximity-Search Query. Such manipulation of the argument distance/lat/lng leads to sql injection.

This vulnerability is documented as CVE-2026-15300. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More