{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aayecodegeodirectorywordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ayecode:geodirectory:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-104899"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GeoDirectory – WP Business Directory Plugin and Classified Listings Directory (\u003c= 2.8.187)"],"_cs_severities":["high"],"_cs_tags":["lfi","wordpress","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Ayecode"],"content_html":"\u003cp\u003eThe GeoDirectory - WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is affected by a critical Local File Inclusion (LFI) vulnerability identified as CVE-2026-104899. This vulnerability exists in all versions up to and including 2.8.187. The flaw originates from the improper validation of the 'design_type' parameter, which allows unauthenticated attackers to supply arbitrary file paths for inclusion.\u003c/p\u003e\n\u003cp\u003eDefenders should note that the exploit is made trivial by the predictable nature of the required security nonce. The plugin exposes the 'geodir_basic_nonce' via the 'geodir_params' script object on all public frontend pages, allowing any anonymous visitor to retrieve the token necessary to bypass security checks. Successful exploitation enables attackers to include and execute arbitrary .php files, potentially leading to full server compromise, data exfiltration, and unauthorized access to site databases. This represents a significant risk to any WordPress environment utilizing the affected plugin version.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to execute arbitrary PHP code on the underlying web server. This can lead to complete site takeover, persistent backdoor installation, exfiltration of sensitive site configuration data (such as database credentials in wp-config.php), and further lateral movement within the hosting infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the GeoDirectory - WP Business Directory Plugin and Classified Listings Directory to a patched version beyond 2.8.187 immediately.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous GET or POST requests directed at the WordPress site containing the 'design_type' parameter with file path strings or directory traversal sequences.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to block requests containing directory traversal sequences or suspicious file path references in the 'design_type' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:51:07Z","date_published":"2026-10-10T07:51:07Z","id":"https://feed.craftedsignal.io/briefs/2026-10-geodirectory-lfi/","summary":"The GeoDirectory plugin for WordPress is vulnerable to unauthenticated local file inclusion (LFI) via the design_type parameter, allowing remote attackers to execute arbitrary PHP code.","title":"Unauthenticated Local File Inclusion in GeoDirectory WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-geodirectory-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ayecode:geodirectory:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}