CVE-2026-2416Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 3 mentions (2026-02-25); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-25: 3Mentions · 2026-03-02: 1Mentions · 2026-03-31: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-02-25: 1Technical Details · 2026-02-25: 3Technical Details · 2026-03-02: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-13: 102-2503-0203-3104-13
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-253
Disclosure2Patch1
2026-03-021
Disclosure1
2026-03-311
Disclosure1
2026-04-131
Disclosure1
Full discourse6 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    CVE‑2026‑2416 – The Geo Mashup WordPress plugin leaks SQL‑level control via the `sort` parameter, turning a simple map‑widget into a full‑table‑read escape hatch. https://nvd.nist.gov/vuln/detail/CVE-2026-2416

    Post summary

    The post announces CVE‑2026‑2416, describing how the Geo Mashup WordPress plugin allows arbitrary SQL read via the `sort` parameter, but does not provide a PoC, exploit code, or mention active exploitation.

    1002029
    1.4K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-2416 - high 🚨 Geo Mashup <= 1.13.17 - SQL Injection > Geo Mashup WordPress plugin <= 1.13.17 contains a SQL injection caused by insufficien... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-2416 @pdnuclei #NucleiTemplates #cve

    Post summary

    High‑severity SQL injection (CVE‑2026‑2416) discovered in Geo Mashup WordPress plugin <= 1.13.17, with a Project Discovery link provided.

    00001155
    928 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2416 (CVSS:7.5, HIGH) is Awaiting Analysis. The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and i..https://nvd.nist.gov/vuln/detail/CVE-2026-2416 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The Geo Mashup plugin for WordPress is vulnerable to SQL injection via the 'sort' parameter, with a CVSS score of 7.5, but no PoC, exploit, or patch is mentioned.

    0000038
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2416 The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and including, 1.13.17. This is due to insufficient e… https://www.cve.org/CVERecord?id=CVE-2026-2416

    Post summary

    The Geo Mashup plugin for WordPress is vulnerable to SQL injection via the 'sort' parameter in all versions up to 1.13.17.

    0000087
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2416 SQL Injection in WordPress Geo Mashup Plugin via Unauthenticated 'sort' Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2416

    Post summary

    A SQL injection vulnerability (CVE-2026-2416) exists in the WordPress Geo Mashup Plugin via an unauthenticated 'sort' parameter, as reported on Vulmon.

    0000030
    4.0K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-2416: Geo Mashup WordPress plugin lets anyone inject SQL via the sort parameter, leaking or tampering with site data. Update to 1.13.18+ now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-2416 #WordPress #infosec #AppSec

    Post summary

    The advisory highlights an SQL injection flaw in the Geo Mashup WordPress plugin that can be exploited via the sort parameter, and urges users to update to version 1.13.18+ to mitigate the risk.

    0000049
    51 followersView on X

Explore more