Local File Inclusion Vulnerability in GEO my WP Plugin for WordPress
CVE-2026-85200
7.5HIGH
What is CVE-2026-85200?
The GEO my WP plugin for WordPress is susceptible to local file inclusion (LFI) in versions up to 4.5.5.3. The vulnerability, stemming from the gmw_posts_locator_ajax_info_window_loader function, allows unauthenticated users to include and execute arbitrary PHP files on the server. This can lead to unauthorized access to sensitive data, bypassing security measures, and in instances where PHP files can be uploaded, achieving full code execution. In configurations where PEAR is installed with register_argc_argv enabled, attackers may exploit this vulnerability to run arbitrary PHP code remotely, significantly compromising the server's security.
Affected Version(s)
GEO my WP 0 <= 4.5.5.3