Ayecode

Location Manager

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 18.09.2026 07:40:05
  • Zuletzt bearbeitet 18.09.2026 15:17:14

The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter and lack of s...

Exploit
  • EPSS 1.83%
  • Veröffentlicht 21.06.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:52:54

In the Location Manager WordPress plugin before 2.1.0.10, the AJAX action gd_popular_location_list did not properly sanitise or validate some of its POST parameters, which are then used in a SQL statement, leading to unauthenticated SQL Injection iss...