CVE-2026-4060 is a time-based blind SQL injection vulnerability in the Geo Mashup plugin for WordPress affecting all versions up to and including 1.13.18. The flaw is present in handling of the user-controlled sort parameter. The plugin applies esc_sql() to the parameter, but that protection is ineffective in the ORDER BY context because the value is not quoted. A later allowlist-style sanitizer, sanitize_sort_arg(), was introduced in version 1.13.18, but it is only enforced in the AJAX processing path through sanitize_query_args() and not in the render-map.php or template tag code paths. As a result, attacker-controlled input can be appended into existing SQL statements, enabling unauthenticated time-based blind SQL injection against the backend database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
sort parameter. Reduce exposure of public-facing endpoints invoking affected render or template paths, and apply compensating controls such as web application firewall rules designed to detect and block SQL injection attempts. Review database permissions to ensure the WordPress application account has the minimum privileges necessary.Patch, then assume compromise.
sort parameter should be corrected by enforcing strict allowlisting for sortable fields across all code paths, including AJAX, render-map, and template tag handlers, and by avoiding direct interpolation of user input into SQL ORDER BY clauses.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact exploit lab and proof-of-concept for CVE-2026-4060, an unauthenticated time-based blind SQL injection in the WordPress Geo Mashup plugin up to version 1.13.18. The repository contains 5 files: a README documenting the issue and usage, a Docker Compose lab definition, a Python PoC exploit, a Bash setup helper, and a Nuclei detection template. The main exploit logic is in poc.py. It uses Python standard libraries only (argparse, time, urllib.parse, urllib.request). The script first checks for plugin presence by requesting /wp-content/plugins/geo-mashup/readme.txt and parsing the Stable tag version. It then confirms SQL injection by sending a SLEEP-based payload in the sort parameter to the unauthenticated render-map endpoint: /?geo_mashup_content=render-map&map_content=global&sort=<payload>. If the response is delayed and contains GeoMashup.createMap, the script proceeds to blind extraction. Extraction is implemented through repeated requests using IF(ORD(SUBSTRING((query),position,1))=ordinal,SLEEP(5),0), allowing character-by-character recovery of SQL query results without relying on quotes. The script is hardcoded to extract VERSION(), DATABASE(), and USER(), making it operational rather than a minimal PoC. It does not provide arbitrary command execution or a shell; its capability is database information disclosure through blind SQLi. The repository also includes nuclei/CVE-2026-4060.yaml, a two-step Nuclei template that first verifies plugin presence/version via /wp-content/plugins/geo-mashup/readme.txt and then sends a time-delay payload to the vulnerable render-map endpoint. This reduces false positives by ensuring the plugin exists and is at a vulnerable version before attempting the SQLi check. The docker-compose.yml and setup.sh files create a reproducible local lab: MariaDB 11.4, WordPress 6.8.2 on Apache/PHP 8.2, and WP-CLI automation that installs Geo Mashup 1.13.18, activates it, and seeds a geo-tagged post so the endpoint returns valid map content. This shows the repository’s purpose is both demonstration and validation of the vulnerability, with exploit and detection artifacts included.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.