Impact
The GeoDirectory WordPress plugin contains a Local File Inclusion flaw that allows an unauthenticated user to supply a 'design_type' parameter and cause the server to include and execute arbitrary PHP files. This can lead to full code execution, data theft, or bypassing of access controls. The vulnerability is rooted in improper validation of the parameter and a publicly exposed nonce. The impact is to compromise the entire site because the attacker can execute any PHP code on the server.
Affected Systems
PaloTia’s GeoDirectory – WP Business Directory Plugin and Classified Listings Directory, versions up to and including 2.8.187. All WordPress installations using these plugin versions are affected.
Risk and Exploitability
The flaw has a CVSS score of 8.1, indicating high severity. No EPSS data is available, and it is not listed in the CISA KEV catalog, but the vulnerability can be exploited by simply sending a crafted request to a public page, as the necessary nonce is provided to any visitor. The attack requires no authentication or privileged access, making exploitation highly likely if the site remains on a vulnerable version.
OpenCVE Enrichment