White Rabbitx[verified]@TheRabbitPyDisclosure
The post announces CVE‑2026‑2416, describing how the Geo Mashup WordPress plugin allows arbitrary SQL read via the `sort` parameter, but does not provide a PoC, exploit code, or mention active exploitation.
Volerion[verified]@VolerionSecPatch
The advisory highlights an SQL injection flaw in the Geo Mashup WordPress plugin that can be exploited via the sort parameter, and urges users to update to version 1.13.18+ to mitigate the risk.
pdnuclei-bot@pdnuclei_botDisclosure
High‑severity SQL injection (CVE‑2026‑2416) discovered in Geo Mashup WordPress plugin <= 1.13.17, with a Project Discovery link provided.
CRAC Learning - Tech@cracbotDisclosure
The Geo Mashup plugin for WordPress is vulnerable to SQL injection via the 'sort' parameter, with a CVSS score of 7.5, but no PoC, exploit, or patch is mentioned.
CVE@CVEnewDisclosure
The Geo Mashup plugin for WordPress is vulnerable to SQL injection via the 'sort' parameter in all versions up to 1.13.17.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A SQL injection vulnerability (CVE-2026-2416) exists in the WordPress Geo Mashup Plugin via an unauthenticated 'sort' parameter, as reported on Vulmon.