Impact
The vulnerability is a local file inclusion flaw in the GEO my WP plugin that allows an unauthenticated attacker to include arbitrary .php files and execute code. This leads to full remote code execution in environments where PEAR register_argc_argv is enabled.
Affected Systems
The WordPress plugin GEO my WP from vendor ninjew, up to and including version 4.5.5.3, is vulnerable. All installations running this or earlier versions are at risk if the gmw_posts_locator_ajax_info_window_loader endpoint is exposed.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity impact. The EPSS score is 3%, indicating a moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. It can be exploited without authentication by sending an HTTP request to the gmw_posts_locator_ajax_info_window_loader AJAX endpoint. It is inferred that PHP file uploads may be allowed, enabling an attacker to upload a malicious script and then trigger the vulnerable inclusion. In environments where PEAR register_argc_argv is enabled, the inclusion can be leveraged to write and execute arbitrary PHP code, providing full remote code execution.
OpenCVE Enrichment