What happened
A security weakness in The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all is being tracked as CVE-2026-85200. CVE-2026-85200 puts affected The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all systems at risk when the vulnerable service or function is reachable from attacker-controlled network traffic. The affected release boundary in the available advisory material is up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_ The GEO my WP plugin for WordPress; teams should compare that boundary with the versions actually running in production.
The reported path can be reached without an authenticated session, increasing exposure wherever the vulnerable interface is network reachable. Unauthenticated exposure changes the operational response because defenders cannot assume that an attacker would already need a compromised account before reaching the vulnerable function.
The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4 5 5 3 via the gmw_posts_locator_ajax_info_window_loader function. The available advisory information identifies up to, and including, 4 5 5 3 via the gmw_posts_locator_ajax_ The GEO my WP plugin for WordPress as affected versions.
Organizations using The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all should first confirm whether affected versions are externally or internally reachable from networks an attacker could access. The available description indicates that the vulnerable path can be reached remotely or from an untrusted network, so the exposure of The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all becomes part of the attack condition.
The important point is that running an affected version of The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all creates exposure, while an actual compromise still depends on whether the attacker can reach the trigger conditions described above. This makes it possible for unauthenticated attackers to include and execute arbitrary.
The issue currently carries a HIGH 7 5 severity signal in the CyberDeltaForce record. php files on the server, allowing the execution of any PHP code in those files. Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
Apply the vendor patch or mitigation for CVE-2026-85200 and validate the affected path after remediation. The current source set does not report active exploitation of CVE-2026-85200; that status should be monitored rather than treated as proof that exploitation is impossible.
The most useful validation after remediation is to confirm that the vulnerable path no longer permits the reported behavior and that the deployed release matches the vendor's corrected version. So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Reference sources
Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.
What security teams should do now
- Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
- Apply the vendor patch or mitigation for CVE-2026-85200 and validate the affected path after remediation.
What is not yet confirmed
- So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.