THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-85200 (HIGH 7.5) — The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on t

[NVD] CVE-2026-85200 (HIGH 7.5) — The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on t

mednvdPublished 2026-09-12

CVE-2026-85200 CVSS: 7.5 HIGH Published: 2026-09-12T08:16:24.810

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85200