PatchSiren cyber security CVE debrief
CVE-2026-104899 paoltaia CVE debrief
The GeoDirectory plugin for WordPress, versions up to and including 2.8.187, is vulnerable to Local File Inclusion. This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on the server, potentially bypassing access controls, obtaining sensitive data, or achieving code execution. The vulnerability is due to insufficient validation of user input in the 'design_type' parameter. WordPress site administrators, security teams, and developers using the GeoDirectory plugin should assess exposure and apply patches or mitigations to prevent potential exploitation. The required nonce for exploitation is trivially obtainable by any anonymous visitor, as
- Vendor
- paoltaia
- Product
- GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress site administrators, security teams, and developers using the GeoDirectory plugin should assess exposure and apply patches or mitigations to prevent potential exploitation.
Why it matters
The GeoDirectory plugin vulnerability allows unauthenticated Local File Inclusion, potentially leading to access control bypass, sensitive data exposure, or code execution. WordPress site administrators and security teams should assess exposure and apply patches or mitigations.
- Potential bypass of access controls
- Possible theft of sensitive data
- Risk of code execution in cases where .php file types can be uploaded and included
- Need for verification of affected versions and remediation status
Technical summary
The GeoDirectory plugin for WordPress is vulnerable to Local File Inclusion in versions up to and including 2.8.187. This allows unauthenticated attackers to include and execute arbitrary PHP files on the server, potentially bypassing access controls, obtaining sensitive data, or achieving code execution. The vulnerability is due to insufficient validation of user input in the 'design_type' parameter, allowing attackers to manipulate file paths and execute malicious code. The required nonce is trivially obtainable by any anonymous visitor, making exploitation more feasible.
Defensive priority
High priority for WordPress site administrators and security teams to assess exposure and apply patches or mitigations.
Recommended defensive actions
- Assess exposure by checking if the GeoDirectory plugin version is 2.8.187 or earlier
- Apply patches or updates to the GeoDirectory plugin to address the vulnerability
- Monitor for suspicious activity or potential exploitation attempts
- Consider implementing additional security controls, such as restricting access to sensitive files or directories
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected versions and potential impact. However, limited information is available on exploitation or victim data. The vulnerability is confirmed to exist in versions up to and including 2.8.187 of the GeoDirectory plugin. Defenders should verify the presence of affected versions in their environments and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104899 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104899
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104899 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104899
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
GeoDirectory <= 2.8.187 - Unauthenticated Local File Inclusion via 'design_type' Parameter
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104899.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.187/includes/widgets/class-geodir-widget-tags.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.187/includes/class-geodir-ajax.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.187/includes/template-functions.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/AyeCode/geodirectory/commit/2357d640dad7973988742a6706b3a857b6b05d52
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3725126/geodirectory/trunk/includes/widgets/class-geodir-widget-tags.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.