CVE-2026-52715 is an unauthenticated SQL injection vulnerability affecting the GEO my WordPress plugin for WordPress in versions up to and including 4.5.5. The available information identifies the issue as a CWE-89 flaw but does not specify the exact vulnerable parameter, endpoint, or function. Based on the advisory data, a remote attacker can supply crafted input to the plugin and cause unsafe SQL query execution without authentication. The vulnerability is network-exploitable and requires no user interaction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a self-contained educational PoC/lab for CVE-2026-52715 affecting GEO my WordPress <= 4.5.5. It is not a standalone exploit script repository; instead it packages a vulnerable copy of the plugin plus Dockerized WordPress/MariaDB infrastructure and extensive documentation describing the exploit chain. The README is the primary exploit artifact: it explains that unauthenticated SQL injection is reachable from any public page containing a [gmw] shortcode by sending GET requests with action=fs and malicious swlatlng/nelatlng values. It documents blind exploitation techniques including time-based SLEEP(), boolean-based inference via the plugin’s total_results behavior, and character-by-character exfiltration using CASE WHEN and SUBSTRING under comma restrictions. Repository structure: top-level files include README.md, docker-compose.yml, and docker/Dockerfile. The docker/geo-my-wp directory contains the vulnerable GEO my WP 4.5.5 plugin source copied into the lab. Most of the 100 files are upstream plugin assets (PHP, JS, CSS, fonts, third-party libraries). The Docker setup exposes WordPress on port 3080 and mounts the vulnerable plugin into /var/www/html/wp-content/plugins/geo-my-wp. The included plugin metadata confirms version 4.5.5. Exploit capability: unauthenticated web SQL injection leading to arbitrary database read from WordPress/MariaDB. The PoC targets public search/map boundary handling rather than privileged AJAX handlers. No weaponized automation or reusable exploit client is present in the provided content, so maturity is best classified as POC. The repository also documents the patched version behavior (4.5.5.1+) and mitigation guidance.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.