THREAT OPS › Threat News › [NVD] CVE-2026-85200 (HIGH 7.5) — The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on t
[NVD] CVE-2026-85200 (HIGH 7.5) — The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on t
CVE-2026-85200 CVSS: 7.5 HIGH Published: 2026-09-12T08:16:24.810
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in t
Indicators of compromise
- CVE-2026-85200cve
- 4.5.5.3ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85200