CVE-2026-104899
Published 10 October 2026 · tracked since 10 October 2026
Description
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.8.187 via the 'design_type' parameter parameter. This makes it possible for unauthenticated attackers to include and ex
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105885 HIGH 8.8
- CVE-2026-91136 HIGH 7.5
- CVE-2026-96662 HIGH 7.5
- CVE-2026-93945 CRITICAL 9.8
- CVE-2026-93936 CRITICAL 9.8
- CVE-2026-93937 CRITICAL 9.8
- CVE-2026-93938 CRITICAL 9.8
- CVE-2026-93940 CRITICAL 9.8
- CVE-2026-93941 CRITICAL 9.8
- CVE-2026-93942 CRITICAL 9.8