Geomywp
Geomywp GEO MY Wordpress: vulnerabilidades y CVE
Geomywp GEO MY Wordpress tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-52715 | Crítica (9.3) | 0.40% | — | 16 jun 2026 | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. |
| CVE-2024-9422 | Media (6.6) | 0.75% | — | 22 nov 2024 | The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the… |
| CVE-2024-47327 | Alta (7.1) | 0.32% | — | 6 oct 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyal Fitoussi GEO my WordPress geo-my-wp allows Reflected XSS.This issue affects GEO my WordPress: from n/a through… |
| CVE-2024-6330 | Crítica (9.8) | 2.1% | — | 19 ago 2024 | The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution. |
| CVE-2024-32097 | Media (5.4) | 0.21% | — | 15 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.1. |
| CVE-2023-52134 | Alta (7.2) | 0.54% | — | 31 dic 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eyal Fitoussi GEO my WordPress.This issue affects GEO my WordPress: from n/a through 4.0.2. |
| CVE-2023-5467 | Media (5.4) | 0.41% | — | 10 oct 2023 | The GEO my WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.