{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/ayecode/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-19091"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GeoDirectory"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","wordpress","arbitrary-file-deletion"],"_cs_type":"advisory","_cs_vendors":["AyeCode"],"content_html":"\u003cp\u003eThe GeoDirectory plugin for WordPress (all versions up to and including 2.8.169) is affected by a critical vulnerability, tracked as CVE-2026-19091, which permits arbitrary file deletion on the hosting server. The vulnerability resides within the \u003ccode\u003edelete_revision\u003c/code\u003e function, which fails to properly validate file paths during the deletion process. Authenticated attackers with subscriber-level access can manipulate the system by crafting specific queries to bypass consistency checks, effectively forcing the application to unlink files controlled via attachment metadata.\u003c/p\u003e\n\u003cp\u003eThis issue is significant because it allows an attacker to delete critical application files, such as 'wp-config.php'. By deleting this configuration file, an attacker can trigger a re-installation process or manipulate the application environment, potentially facilitating remote code execution or total site compromise. The exploit involves converting an auto-draft listing into an attachment to bypass validation mechanisms, demonstrating a breakdown in input sanitization and post-type verification within the plugin's core logic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the deletion of arbitrary files on the WordPress server, leading to potential service disruption, unauthorized installation redirection, and full remote code execution if sensitive configuration files are removed. This affects all websites utilizing the GeoDirectory plugin version 2.8.169 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the GeoDirectory plugin to the latest patched version available from the vendor.\u003c/li\u003e\n\u003cli\u003eAudit access logs for subscriber-level users attempting to POST to the plugin's revision or attachment handling endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized file modification or deletion events targeting core WordPress files (e.g., wp-config.php).\u003c/li\u003e\n\u003cli\u003eEnable web application firewall rules to detect and block suspicious requests containing post_type=attachment parameters in unauthorized contexts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T21:51:03Z","date_published":"2026-08-11T21:51:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-geodirectory-arbitrary-file-deletion/","summary":"The GeoDirectory WordPress plugin contains an arbitrary file deletion vulnerability (CVE-2026-19091) allowing authenticated attackers to delete critical files and potentially achieve remote code execution.","title":"Arbitrary File Deletion in GeoDirectory Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-geodirectory-arbitrary-file-deletion/"}],"language":"en","title":"CraftedSignal Threat Feed - AyeCode","version":"https://jsonfeed.org/version/1.1"}