{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/geo-my-wp--4.5.5.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:geomywp:geo_my_wp:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-85200"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GEO my WP (\u003c= 4.5.5.3)"],"_cs_severities":["high"],"_cs_tags":["wordpress","lfi","vulnerability","rce"],"_cs_type":"advisory","_cs_vendors":["GEO my WP"],"content_html":"\u003cp\u003eThe GEO my WP plugin for WordPress (versions up to and including 4.5.5.3) contains a critical security flaw involving improper input validation within the gmw_posts_locator_ajax_info_window_loader function. This vulnerability enables unauthenticated attackers to perform Local File Inclusion (LFI). By manipulating input parameters, an attacker can force the application to include and execute arbitrary PHP files residing on the web server.\u003c/p\u003e\n\u003cp\u003eThis flaw allows attackers to bypass standard access controls and potentially exfiltrate sensitive application data. Of particular concern is the escalation path in server configurations where the PEAR framework is installed with the register_argc_argv configuration enabled. In these environments, attackers can leverage the LFI vulnerability to inject and execute arbitrary PHP code, resulting in full remote code execution (RCE). Security teams should prioritize patching or disabling the vulnerable component immediately.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read sensitive local files, bypass application-level authentication, and achieve full remote code execution on the underlying server if specific PHP environment configurations are present. This impact covers all WordPress instances running GEO my WP version 4.5.5.3 or older.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the GEO my WP plugin to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eAudit server-side PHP configurations, specifically the status of the PEAR library and the register_argc_argv setting, to reduce the risk of RCE escalation.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to detect and block abnormal directory traversal or file inclusion attempts targeting the gmw_posts_locator_ajax_info_window_loader function.\u003c/li\u003e\n\u003cli\u003eEnable and monitor server-side web access logs for anomalous HTTP requests targeting AJAX endpoints with parameter values containing directory navigation sequences (e.g., ../).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-12T09:19:15Z","date_published":"2026-09-12T09:19:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-geo-my-wp-lfi/","summary":"The GEO my WP plugin for WordPress is vulnerable to unauthenticated local file inclusion (LFI) via the gmw_posts_locator_ajax_info_window_loader function, which can be escalated to remote code execution in specific PEAR-enabled environments.","title":"Local File Inclusion Vulnerability in GEO my WP WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-geo-my-wp-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - GEO My WP (\u003c= 4.5.5.3)","version":"https://jsonfeed.org/version/1.1"}