The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHPs execution context, which leads to Remote Code Execution.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Geo_my_wordpress | Geomywp | * | 4.5.0.2 (excluding) |
References