Description
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The required nonce is trivially obtainable by any anonymous visitor, as the geodir_basic_nonce value is localized to every public frontend page via the geodir_params script object, meaning no authentication, user interaction, or specific site content is required to exploit this vulnerability.
Published: 2026-10-10
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Local File Inclusion
Action: Immediate Patch
AI Analysis

Impact

The GeoDirectory WordPress plugin contains a Local File Inclusion flaw that allows an unauthenticated user to supply a 'design_type' parameter and cause the server to include and execute arbitrary PHP files. This can lead to full code execution, data theft, or bypassing of access controls. The vulnerability is rooted in improper validation of the parameter and a publicly exposed nonce. The impact is to compromise the entire site because the attacker can execute any PHP code on the server.

Affected Systems

PaloTia’s GeoDirectory – WP Business Directory Plugin and Classified Listings Directory, versions up to and including 2.8.187. All WordPress installations using these plugin versions are affected.

Risk and Exploitability

The flaw has a CVSS score of 8.1, indicating high severity. No EPSS data is available, and it is not listed in the CISA KEV catalog, but the vulnerability can be exploited by simply sending a crafted request to a public page, as the necessary nonce is provided to any visitor. The attack requires no authentication or privileged access, making exploitation highly likely if the site remains on a vulnerable version.

Generated by OpenCVE AI on October 10, 2026 at 06:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GeoDirectory to version 2.8.188 or later.
  • If an upgrade is not immediately possible, remove or sanitize the 'design_type' query parameter in the plugin’s request handling code, ensuring it cannot be used to reference files outside the intended directories.
  • Apply a web application firewall rule to block any request that attempts to include files via the design_type parameter, and monitor logs for suspicious file inclusion attempts.

Generated by OpenCVE AI on October 10, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The required nonce is trivially obtainable by any anonymous visitor, as the geodir_basic_nonce value is localized to every public frontend page via the geodir_params script object, meaning no authentication, user interaction, or specific site content is required to exploit this vulnerability.
Title GeoDirectory <= 2.8.187 - Unauthenticated Local File Inclusion via 'design_type' Parameter
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T05:31:02.786Z

Reserved: 2026-10-02T15:13:20.018Z

Link: CVE-2026-104899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T06:16:40.160

Modified: 2026-10-10T06:16:40.160

Link: CVE-2026-104899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T06:30:18Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')