Unauthenticated Local File Inclusion in GeoDirectory WordPress Plugin
The GeoDirectory plugin for WordPress is vulnerable to unauthenticated local file inclusion (LFI) via the design_type parameter, allowing remote attackers to execute arbitrary PHP code.
CVE search metadata
CVE search record: CVE-2026-104899. Severity: high. CVSS: 8.1. KEV: no. Product: GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (<= 2.8.187). Brief: Unauthenticated Local File Inclusion in GeoDirectory WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-geodirectory-lfi/
The GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is affected by a critical Local File Inclusion (LFI) vulnerability identified as CVE-2026-104899. This vulnerability exists in all versions up to and including 2.8.187. The flaw originates from the improper validation of the 'design_type' parameter, which allows unauthenticated attackers to supply arbitrary file paths for inclusion.
Defenders should note that the exploit is made trivial by the predictable nature of the required security nonce. The plugin exposes the 'geodir_basic_nonce' via the 'geodir_params' script object on all public frontend pages, allowing any anonymous visitor to retrieve the token necessary to bypass security checks. Successful exploitation enables attackers to include and execute arbitrary .php files, potentially leading to full server compromise, data exfiltration, and unauthorized access to site databases. This represents a significant risk to any WordPress environment utilizing the affected plugin version.
Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary PHP code on the underlying web server. This can lead to complete site takeover, persistent backdoor installation, exfiltration of sensitive site configuration data (such as database credentials in wp-config.php), and further lateral movement within the hosting infrastructure.
Recommendation
Prioritized actions for security teams:
- Update the GeoDirectory - WP Business Directory Plugin and Classified Listings Directory to a patched version beyond 2.8.187 immediately.
- Audit web server access logs for anomalous GET or POST requests directed at the WordPress site containing the 'design_type' parameter with file path strings or directory traversal sequences.
- Implement a Web Application Firewall (WAF) rule to block requests containing directory traversal sequences or suspicious file path references in the 'design_type' parameter.
Immediate actions
Deploy WAF rule to block exploitation of CVE-2026-104899
Mitigations
Upgrade GeoDirectory plugin to a version higher than 2.8.187
CVE-2026-104899
Detection coverage 1
Detect CVE-2026-104899 Exploitation - Unauthenticated LFI via GeoDirectory Plugin
highDetects exploitation attempts against CVE-2026-104899 where an unauthenticated actor sends a request to the server with a malicious path in the design_type parameter.
Detection queries are available on the platform. Get full rules →