Geo Mashup WordPress plugin <= 1.13.17 contains a SQL injection caused by insufficient escaping of the 'sort' parameter, letting unauthenticated attackers extract sensitive database information remotely.
id: CVE-2026-2416
info:
name: Geo Mashup <= 1.13.17 - SQL Injection
author: Shivam Kamboj
sev
...