Skip to content
Threat Feed
high advisory

Unauthenticated Local File Inclusion in GeoDirectory WordPress Plugin

The GeoDirectory plugin for WordPress is vulnerable to unauthenticated local file inclusion (LFI) via the design_type parameter, allowing remote attackers to execute arbitrary PHP code.

CVE search metadata

CVE search record: CVE-2026-104899. Severity: high. CVSS: 8.1. KEV: no. Product: GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (<= 2.8.187). Brief: Unauthenticated Local File Inclusion in GeoDirectory WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-geodirectory-lfi/

The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is affected by a critical Local File Inclusion (LFI) vulnerability identified as CVE-2026-104899. This vulnerability exists in all versions up to and including 2.8.187. The flaw originates from the improper validation of the 'design_type' parameter, which allows unauthenticated attackers to supply arbitrary file paths for inclusion.

Defenders should note that the exploit is made trivial by the predictable nature of the required security nonce. The plugin exposes the 'geodir_basic_nonce' via the 'geodir_params' script object on all public frontend pages, allowing any anonymous visitor to retrieve the token necessary to bypass security checks. Successful exploitation enables attackers to include and execute arbitrary .php files, potentially leading to full server compromise, data exfiltration, and unauthorized access to site databases. This represents a significant risk to any WordPress environment utilizing the affected plugin version.

Impact

Successful exploitation allows unauthenticated remote attackers to execute arbitrary PHP code on the underlying web server. This can lead to complete site takeover, persistent backdoor installation, exfiltration of sensitive site configuration data (such as database credentials in wp-config.php), and further lateral movement within the hosting infrastructure.

Recommendation

Prioritized actions for security teams:

  • Update the GeoDirectory - WP Business Directory Plugin and Classified Listings Directory to a patched version beyond 2.8.187 immediately.
  • Audit web server access logs for anomalous GET or POST requests directed at the WordPress site containing the 'design_type' parameter with file path strings or directory traversal sequences.
  • Implement a Web Application Firewall (WAF) rule to block requests containing directory traversal sequences or suspicious file path references in the 'design_type' parameter.

Immediate actions

Deploy WAF rule to block exploitation of CVE-2026-104899

SOC 24h

Mitigations

Upgrade GeoDirectory plugin to a version higher than 2.8.187

immediate IT Operations

CVE-2026-104899

Detection coverage 1

Detect CVE-2026-104899 Exploitation - Unauthenticated LFI via GeoDirectory Plugin

high

Detects exploitation attempts against CVE-2026-104899 where an unauthenticated actor sends a request to the server with a malicious path in the design_type parameter.

sigma tactics: initial_access techniques: T1210 sources: webserver

Detection queries are available on the platform. Get full rules →