Executive brief
GeoDirectory is a popular WordPress plugin that allows businesses to create directory and classified listings on their websites. A vulnerability in the file deletion function permits authenticated subscribers to delete arbitrary files from the server, including critical configuration files like wp-config.php, potentially leading to remote code execution and complete site compromise.
Technical details
The delete_revision function in GeoDirectory versions up to 2.8.169 lacks sufficient file path validation when processing file deletion requests. Attackers with subscriber-level privileges can bypass consistency checks by placing post_type=attachment exclusively in the query string, converting an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata. The delete_revision handler then dereferences and unlinks these paths without validating post-type or file paths, enabling deletion of arbitrary server files. This is a privilege escalation and arbitrary file deletion vulnerability; successful exploitation can lead to remote code execution when critical files are deleted.
Affected products
- AyeCode GeoDirectory up to and including 2.8.169
Timeline
- 2026-08-11: disclosed: CVE-2026-19091 published