CVE-2026-103913 WordPress GeoDirectory 插件 SQL 注入漏洞
影响攻击者可注入 SQL 语句窃取数据库敏感信息
GeoDirectory 是 WordPress 的目录/列表类插件。其 2.8.186 及之前版本在保存列表的经纬度坐标时缺乏转义与数值校验,坐标值被直接拼接进 geodir_gps_query_part() 的距离子表达式,最终由公开的 wp_ajax_nopriv_geodir_widget_listings 处理器执行,导致 SQL 注入。
影响范围
GeoDirectory 插件 2.8.186 及之前版本(依据 CVE 描述)。
漏洞详情
漏洞类型为 SQL 注入。成因是保存列表时对 latitude/longitude 坐标值未做充分转义和数值校验,随后这些值被直接字符串拼接进距离计算 SQL 子表达式。攻击者以 Subscriber 及以上权限提交恶意坐标,并通过 set_post=<待审列表 ID> 与 sort_by=distance_asc 参数触发未认证 AJAX 处理器,从而向原查询追加 SQL 语句。
利用条件与风险
利用需具备 Subscriber 及以上账户并存在待审列表,但触发接口为 nopriv 公开 AJAX,实战中可被用于读取数据库敏感信息,风险较高。
修复建议
官方修复方案暂无公开信息,建议升级至 2.8.186 之后的安全版本;临时缓解可对坐标参数强制数值校验与参数化查询,或限制相关 AJAX 接口访问。
The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. This is due to insufficient escaping and the absence of numeric validation on coordinate values when a listing is saved, combined with the direct string interpolation of those values into a distance sub-expression in geodir_gps_query_part() that is later executed by the public wp_ajax_nopriv_geodir_widget_listings handler when a caller supplies set_post= and sort_by=distance_asc. This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.