Geo Mashup <= 1.13.17 - SQL Injection
Geo Mashup WordPress plugin <= 1.13.17 contains a SQL injection caused by insufficient escaping of the 'sort' parameter, letting unauthenticated attackers extract sensitive database information remotely.
PoC 已收录geo-mashup
CVSS—EPSS 1.4%