CVE-2026-103913 | paoltaia GeoDirectory Plugin up to 2.8.186 on WordPress GPS Query geodir_gps_query_part set_post/sort_by sql injection
A vulnerability described as critical has been identified in paoltaia GeoDirectory Plugin up to 2.8.186 on WordPress. This affects the function geodir_gps_query_part of the component GPS Query. Executing a manipulation of the argument set_post/sort_by can lead to sql injection.
This vulnerability appears as CVE-2026-103913. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More