WordPress 的 GeoDirectory 插件在 2.8.186 及以下版本中存在通过 listings(列表项)中存储的经度和纬度坐标触发的 SQL 注入漏洞。该漏洞源于在保存列表项时,对坐标值缺乏充分的转义处理,且未进行数值类型验证;同时,这些坐标值会被直接以字符串插值的方式拼接到 函数中的距离子表达式中。该查询随后由公共 AJAX 处理器 执行,当攻击者提供 和 参数时会触发此逻辑。此漏洞允许具有订阅者(Subscriber)及以上权限的已认证攻击者,将额外的 SQL 查询注入到现有查询中,从而可能从
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | ≤ 2.8.186 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| paoltaia | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | 0 ~ 2.8.186 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet