PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104899 paoltaia CVE debrief

The GeoDirectory plugin for WordPress, versions up to and including 2.8.187, is vulnerable to Local File Inclusion. This vulnerability allows unauthenticated attackers to include and execute arbitrary PHP files on the server, potentially bypassing access controls, obtaining sensitive data, or achieving code execution. The vulnerability is due to insufficient validation of user input in the 'design_type' parameter. WordPress site administrators, security teams, and developers using the GeoDirectory plugin should assess exposure and apply patches or mitigations to prevent potential exploitation. The required nonce for exploitation is trivially obtainable by any anonymous visitor, as

Vendor
paoltaia
Product
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

WordPress site administrators, security teams, and developers using the GeoDirectory plugin should assess exposure and apply patches or mitigations to prevent potential exploitation.

Why it matters

The GeoDirectory plugin vulnerability allows unauthenticated Local File Inclusion, potentially leading to access control bypass, sensitive data exposure, or code execution. WordPress site administrators and security teams should assess exposure and apply patches or mitigations.

  • Potential bypass of access controls
  • Possible theft of sensitive data
  • Risk of code execution in cases where .php file types can be uploaded and included
  • Need for verification of affected versions and remediation status

Technical summary

The GeoDirectory plugin for WordPress is vulnerable to Local File Inclusion in versions up to and including 2.8.187. This allows unauthenticated attackers to include and execute arbitrary PHP files on the server, potentially bypassing access controls, obtaining sensitive data, or achieving code execution. The vulnerability is due to insufficient validation of user input in the 'design_type' parameter, allowing attackers to manipulate file paths and execute malicious code. The required nonce is trivially obtainable by any anonymous visitor, making exploitation more feasible.

Defensive priority

High priority for WordPress site administrators and security teams to assess exposure and apply patches or mitigations.

Recommended defensive actions

  • Assess exposure by checking if the GeoDirectory plugin version is 2.8.187 or earlier
  • Apply patches or updates to the GeoDirectory plugin to address the vulnerability
  • Monitor for suspicious activity or potential exploitation attempts
  • Consider implementing additional security controls, such as restricting access to sensitive files or directories
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected versions and potential impact. However, limited information is available on exploitation or victim data. The vulnerability is confirmed to exist in versions up to and including 2.8.187 of the GeoDirectory plugin. Defenders should verify the presence of affected versions in their environments and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104899 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104899

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104899 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104899

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • GeoDirectory <= 2.8.187 - Unauthenticated Local File Inclusion via 'design_type' Parameter

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/104xxx/CVE-2026-104899.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.187/includes/widgets/class-geodir-widget-tags.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.187/includes/class-geodir-ajax.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/geodirectory/tags/2.8.187/includes/template-functions.php

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AyeCode/geodirectory/commit/2357d640dad7973988742a6706b3a857b6b05d52

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/changeset/3725126/geodirectory/trunk/includes/widgets/class-geodir-widget-tags.php

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.