Junglewise Threat Intelligence

CVE-2026-19091: AyeCode GeoDirectory arbitrary file deletion via insufficient path validation

CVE-2026-19091 · Severity: high · CVSS 8.1 · Published 2026-08-11

Vendors: AyeCode.

Executive brief

GeoDirectory is a popular WordPress plugin that allows businesses to create directory and classified listings on their websites. A vulnerability in the file deletion function permits authenticated subscribers to delete arbitrary files from the server, including critical configuration files like wp-config.php, potentially leading to remote code execution and complete site compromise.

Technical details

The delete_revision function in GeoDirectory versions up to 2.8.169 lacks sufficient file path validation when processing file deletion requests. Attackers with subscriber-level privileges can bypass consistency checks by placing post_type=attachment exclusively in the query string, converting an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata. The delete_revision handler then dereferences and unlinks these paths without validating post-type or file paths, enabling deletion of arbitrary server files. This is a privilege escalation and arbitrary file deletion vulnerability; successful exploitation can lead to remote code execution when critical files are deleted.

Affected products

  • AyeCode GeoDirectory up to and including 2.8.169

Timeline

  • 2026-08-11: disclosed: CVE-2026-19091 published

References