Sceawere

Vulnerability Detail

CVE-2026-104899UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GeoDirectory Local File Inclusion

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
2h ago
Vendor
paoltaia
Product
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory
Attack Type
CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. The required nonce is trivially obtainable by any anonymous visitor, as the geodir_basic_nonce value is localized to every public frontend page via the geodir_params script object, meaning no authentication, user interaction, or specific site content is required to exploit this vulnerability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-10-10T06:16:40.160Z",
  "pubdate": "2026-10-10T06:16:40.160Z",
  "executiveSummary": "The GeoDirectory plugin for WordPress is vulnerable to an unauthenticated Local File Inclusion (LFI) vulnerability residing in the 'design_type' parameter.\nThis vulnerability impacts all plugin versions up to and including 2.8.187.\nThe flaw permits remote, unauthenticated attackers to include and execute arbitrary PHP files located on the underlying web server.\nExploitation allows for remote code execution, unauthorized access to sensitive system data, and potential compromise of the entire WordPress installation.\nThe attack vector is facilitated by the trivial accessibility of the 'geodir_basic_nonce', which is exposed to all public-facing users via the 'geodir_params' JavaScript object, removing the requirement for legitimate authentication or user interaction.\nGiven the nature of LFI, successful exploitation results in full server-side script execution, posing a critical risk to the confidentiality, integrity, and availability of the host environment.",
  "technicalDetails": "The vulnerability is categorized as an improper neutralization of input during web page generation, specifically manifesting as an LFI flaw within the GeoDirectory plugin's handling of the 'design_type' parameter.\nThe root cause lies in the application's failure to adequately sanitize or validate user-supplied input before passing it to filesystem inclusion functions (e.g., include, require).\nAn attacker can manipulate the 'design_type' parameter to traverse directory structures and point the server-side inclusion mechanism to malicious files accessible within the file system.\nBecause the application executes these files as PHP code, an attacker can achieve Remote Code Execution (RCE) if they are able to upload a crafted file to the server or utilize existing reachable files that contain attacker-controllable input.\nThe exploitation process is simplified by the exposure of the 'geodir_basic_nonce'. This value is required for the request but is localized to the frontend via the 'geodir_params' script object. An attacker can simply scrape this nonce from any public page of the target site without needing an active session or administrative privileges.\nThe attack flow follows these steps: 1. The attacker visits a public page of the target site to retrieve the 'geodir_basic_nonce' from the 'geodir_params' object. 2. The attacker crafts a request containing the nonce and a malicious payload targeting the 'design_type' parameter to facilitate an LFI. 3. The server processes the request, fails to validate the path provided in 'design_type', and includes the specified local file. 4. The server executes the included code within the context of the web server process.\nThis vulnerability affects versions up to 2.8.187 of GeoDirectory. It is exploitable over the network by any unauthenticated visitor. Post-exploitation impact includes, but is not limited to, arbitrary code execution, exfiltration of WordPress configuration files (e.g., wp-config.php), database credential theft, and full site takeover."
}
CVE-2026-104899: GeoDirectory Local File Inclusion (HIGH Severity, CVSS: 8.1) | Sceawere