Product
The GeoDirectory plugin for WordPress is vulnerable to unauthenticated local file inclusion (LFI) via the design_type parameter, allowing remote attackers to execute arbitrary PHP code.