Local File Inclusion Vulnerability in GEO my WP Plugin for WordPress
CVE-2026-85200

7.5HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
12 September 2026

What is CVE-2026-85200?

The GEO my WP plugin for WordPress is susceptible to local file inclusion (LFI) in versions up to 4.5.5.3. The vulnerability, stemming from the gmw_posts_locator_ajax_info_window_loader function, allows unauthenticated users to include and execute arbitrary PHP files on the server. This can lead to unauthorized access to sensitive data, bypassing security measures, and in instances where PHP files can be uploaded, achieving full code execution. In configurations where PEAR is installed with register_argc_argv enabled, attackers may exploit this vulnerability to run arbitrary PHP code remotely, significantly compromising the server's security.

Affected Version(s)

GEO my WP 0 <= 4.5.5.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yck
.