Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POC-GeoLeak-CVE-2026-52715 — PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit time-based/boolean-based + exfiltracion sin comas en payload. | Kitploit
Tools/GitHubGitHub/686f6c61/poc-geoleak-cve-2026-52715
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationPayload DevelopmentLabs & Practice
GitHub
686f6c61/poc-geoleak-cve-2026-52715

POC-GeoLeak-CVE-2026-52715

PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit time-based/boolean-based + exfiltracion sin comas en payload.

View Repository
151 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

GeoLeak — PoC for CVE-2026-52715

Educational Proof of Concept for GeoLeak (CVE-2026-52715), an unauthenticated SQL injection (CVSS 9.3) in the GEO my WordPress <= 4.5.5 plugin for WordPress. The swlatlng and nelatlng map boundary parameters are interpolated without sanitization into the WHERE clause. Self-contained Docker lab + exploit featuring time-based, boolean-based, and character-by-character exfiltration techniques.


Table of Contents

  1. Executive Summary
  2. Legal Notice
  3. Chain Architecture
  4. Requirements
  5. Repository Structure
  6. Quick Start Guide
  7. Exploitation Verification
  8. Technical Analysis
  9. The Official Patch (4.5.5.1)
  10. Mitigation
  11. Credits
  12. License

Executive Summary

CVE-2026-52715 is an SQL injection (CWE-89) in the gmw_get_locations_within_boundaries_sql() function of the GEO my WordPress plugin, affecting all versions <= 4.5.5 and patched since 4.5.5.1 (June 15, 2026). It was discovered by researcher alvarodh5 and published via Patchstack.

The chain dubbed GeoLeak demonstrates how, starting from read-only access to any public page containing the [gmw] shortcode, an attacker can:

  1. Inject arbitrary SQL through the swlatlng (or nelatlng) query string parameter, without cookies, nonce, or authentication.
  2. Force measurable delays with SLEEP() (time-based blind) evaluated for each row of the INNER JOIN against wp_gmw_locations.
  3. Use the "total_results":N oracle that the plugin itself embeds in the map configuration JSON to infer boolean conditions (boolean-based blind).
  4. Exfiltrate the entire database character by character, bypassing the restriction that the payload cannot contain commas (PHP splits the value with explode(',', ...)), using CASE WHEN and SUBSTRING(x FROM n FOR 1).

The result is arbitrary read access to the WordPress database: the wp_users table (password hashes), configuration options, keys, and third-party data stored in plugins.

The PoC verifies the complete extraction of MariaDB's VERSION() using only GET requests.


Legal Notice

This repository contains strictly educational and defensive material.

  • Purpose: demonstrate the exploitation chain for training, self-auditing, and patch validation purposes.
  • Authorized use: run it only against systems you own or for which you have explicit written authorization. The included Docker lab is the only intended environment.
  • Prohibited: any use against third-party systems without consent. The repository author is not responsible for misuse of the material included here.
  • Responsibility: the operator is solely responsible for compliance with applicable legislation (LOPD/GDPR in Spain, CFAA in the US, etc.).

Chain Architecture

┌─────────────────────────────────────────────────────────────────────┐
│  1. Peticion publica sin autenticar                                 │
│     GET /?page_id=5&form=1&action=fs&swlatlng=<payload>&nelatlng=…  │
│     pagina publica con shortcode [gmw form="1"]                     │
└──────────────────────────────────────────────────┬──────────────────┘
                                                   ▼
┌─────────────────────────────────────────────────────────────────────┐
│  2. GMW_Form::set_default_values()                                  │
│     action=fs => formulario marcado como enviado                    │
│     get_form_values() toma $_SERVER['QUERY_STRING']                 │
└──────────────────────────────────────────────────┬──────────────────┘
                                                   ▼
┌─────────────────────────────────────────────────────────────────────┐
│  3. gmw_get_form_values() (gmw-functions.php:512)                   │
│     parse_str($query_string, $output)  sin lista de permitidos      │
│     $output['swlatlng'] llega intacto                               │
└──────────────────────────────────────────────────┬──────────────────┘
                                                   ▼
┌─────────────────────────────────────────────────────────────────────┐
│  4. parse_query_args() (class-gmw-form-core.php:794)                │
│     gmw_swlatlng / gmw_nelatlng copiados a los argumentos de busqueda│
└──────────────────────────────────────────────────┬──────────────────┘
                                                   ▼
┌─────────────────────────────────────────────────────────────────────┐
│  5. gmw_get_locations_within_boundaries_sql() (gmw-functions:669)   │
│     $sw = explode(',', $southwest);                                 │
│     "AND ( gmw_locations.latitude BETWEEN {$sw[0]} AND {$ne[0]} )"  │
│     interpolacion directa: sin prepare, sin validacion              │
└──────────────────────────────────────────────────┬──────────────────┘
                                                   ▼
┌─────────────────────────────────────────────────────────────────────┐
│  6. WP_Query -> $wpdb->get_results()                                │
│     SQL: ... AND ( gmw_locations.latitude BETWEEN                   │
│            1 AND SLEEP(5) AND 40.416775 AND 41 ) ...                │
│     respuesta retardada 5s / total_results = oraculo                │
└─────────────────────────────────────────────────────────────────────┘

Requirements

  • Docker and Docker Compose (tested with Docker 29.4.1 / Compose v5.2.0)
  • curl and awk for the exploit
  • Port 3080 free (or change the mapping in docker-compose.yml)

Repository Structure

POC-GeoLeak-CVE-2026-52715/
├── docker-compose.yml          WordPress 6.8 (PHP 8.2) + MariaDB 11
├── docker/
│   ├── Dockerfile              Imagen WP + WP-CLI + entrypoint del laboratorio
│   ├── lab-entrypoint.sh       Arranque + siembra automatica en el primer boot
│   ├── seed.sh                 Instalacion WP, formulario, post geolocalizado
│   └── geo-my-wp/              Plugin GEO my WordPress 4.5.5 (codigo vulnerable)
├── poc/
│   └── poc.sh                  Exploit: time-based + boolean-based + exfiltracion
├── docs/
│   ├── analisis-tecnico.md     Cadena completa request -> SQL, con codigo
│   └── diff-parche-4.5.5.1-gmw-functions.php.diff   Parche oficial real
├── LICENSE
└── README.md

Quick Start Guide

# 1. Levantar el laboratorio (primer arranque: 60-90 s)
docker compose up -d --build

# 2. Comprobar que la siembra termino
docker compose logs wordpress | grep lab-entrypoint
# [lab-entrypoint] laboratorio listo

# 3. Ejecutar la PoC
./poc/poc.sh

# 4. Destruir el laboratorio
docker compose down -v

Configurable exploit parameters:

TARGET=http://localhost:3080 PAGE_ID=5 FORM_ID=1 SLEEP=5 ./poc/poc.sh

WordPress access: http://localhost:3080 with admin/admin. The page with the vulnerable form is http://localhost:3080/?page_id=5.

Note: the seed row in wp_gmw_locations is essential. The query uses INNER JOIN against that table: without rows the injected WHERE is not evaluated and SLEEP() does not sleep.


Exploitation Verification

Real output from the last run against the lab (August 14, 2026):

Download Tool