The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHPs execution context, which leads to Remote Code Execution.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Geo_my_wordpress |
Geomywp |
* |
4.5.0.2 (excluding) |
References