Junglewise Threat Intelligence

CVE-2026-85200: GEO my WP Local File Inclusion

CVE-2026-85200 · Severity: high · CVSS 7.5 · Published 2026-09-12

Technologies: Fitoussi GEO my WP.

Executive brief

GEO my WP is a popular WordPress plugin for geolocation, mapping, and proximity search functionality. The plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to include and execute arbitrary PHP files from the server, potentially leading to code execution, data theft, or website compromise.

Technical details

The vulnerability is a local file inclusion (LFI) flaw in the gmw_posts_locator_ajax_info_window_loader function affecting all versions up to 4.5.5.3. An unauthenticated attacker can exploit this via a network request to include and execute arbitrary PHP files on the server. In environments where PEAR is installed with register_argc_argv enabled, this can be leveraged to achieve remote code execution. The vulnerability was patched in version 4.5.5.4, released on 2026-09-10.

Affected products

  • Fitoussi GEO my WP up to and including 4.5.5.3

Timeline

  • 2026-09-12: disclosed
  • 2026-09-10: patched: Version 4.5.5.4 released

References