Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-78286: WordPress Geo Controller plugin can let attackers run code
CVE-2026-78286 · published 7 days ago
Summary
The Geo Controller add‑on for WordPress (versions up to 8.9.8) lets anyone on the internet send specially crafted data that can make the server execute whatever code they want. This could let an attacker take control of your website or steal information. Update the plugin to the latest version or disable/remove it immediately.
What to do
- Update infinitum form geo controller to version 8.9.9.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| infinitum form | geo controller |
<= 8.9.8 Fix: upgrade to 8.9.9
|
Original advisory text
WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published27 Aug 2026
Updated3 Sep 2026
First seen27 Aug 2026
Monitor software like this
Free during beta