Impact
Improper control of filename in the Geo Mashup plugin allows an attacker to include local files using PHP's include or require statements. The vulnerability exists in all versions up to and including 1.13.16, meaning an attacker could read sensitive configuration or user files and, in some configurations, execute malicious code. The weakness corresponds to CWE-98, a classic local file inclusion flaw, and carries a CVSS score of 9.8, indicating a high potential for critical impact.
Affected Systems
The Geo Mashup plugin developed by Dylan Kuhn is affected; versions from its earliest release through 1.13.16 are vulnerable. Sites running WordPress with this plugin installed are at risk unless they have upgraded to a newer release.
Risk and Exploitability
Given the EPSS score of less than 1%, exploitation is considered unlikely at present, and the vulnerability is not currently listed in the CISA KEV catalog. However, the high CVSS score reflects a severe potential, and the attack requires the ability to influence the file path parameter used by the plugin, which may be possible from any user context that can access the plugin's options. Because of the critical nature of LFI, administrators should treat this issue as high risk and act promptly.
OpenCVE Enrichment
EUVD