Junglewise Threat Intelligence

CVE-2026-78286: Geo Controller PHP object injection vulnerability

CVE-2026-78286 · Severity: critical · CVSS 9.8 · Published 2026-08-27

Executive brief

Geo Controller is a popular WordPress plugin used to display geographic information on websites. The plugin contains a PHP object injection flaw that allows unauthenticated attackers to execute arbitrary code on affected servers. Websites running vulnerable versions are at immediate risk of complete compromise, including data theft and ransomware deployment.

Technical details

The vulnerability is a PHP object injection (CWE-502) in the Geo Controller WordPress plugin versions 8.9.8 and earlier. The flaw exists in the Geo Controller component and can be exploited without authentication via a network vector. Attackers can craft malicious serialized PHP objects to manipulate server-side processing and achieve remote code execution. The vulnerability has been patched in version 8.9.9; sites should update immediately as exploitation is highly likely.

Affected products

  • Geo Controller Geo Controller <=8.9.8

Timeline

  • 2026-08-25: disclosed: Reported by Supakiad S. (m3ez)
  • 2026-08-27: advisory: CVE-2026-78286 published
  • 2026-08-25: patched: Fixed in version 8.9.9

References