The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. In environments where PEAR is installed with register_argc_argv enabled, this file inclusion can be leveraged to write and execute arbitrary PHP code, achieving full remote code execution.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The GEO my WP WordPress plugin contains a critical Local File Inclusion (LFI) vulnerability in versions up to 4.5.5.3 that allows unauthenticated attackers to include and execute arbitrary PHP files on vulnerable servers. The vulnerability exists in the gmw_posts_locator_ajax_info_window_loader function, which fails to properly validate file paths before inclusion. This is particularly dangerous because it enables attackers to execute arbitrary PHP code without authentication, potentially leading to complete server compromise, sensitive data theft, or lateral movement within the hosting environment. Organizations running WordPress installations with this plugin—especially those using it for location-based features in real estate, local business directories, or mapping applications—face immediate risk of exploitation.
While this CVE currently maps to zero Casky skills due to its recent disclosure, practitioners using Casky.ai's platform would typically detect LFI attack patterns through reconnaissance and execution-phase behaviors. Security teams should monitor for suspicious AJAX requests to the gmw_posts_locator_ajax_info_window_loader endpoint with file path traversal sequences (../, etc.), unusual PHP file inclusions from unexpected directories, and post-exploitation activities like web shell creation or data exfiltration. Extended reasoning analysis would correlate these indicators with CWE-98 (Remote File Inclusion) patterns to identify attack chains. Organizations should immediately audit GEO my WP installations, update to patched versions beyond 4.5.5.3, and review web server logs for signs of exploitation or reconnaissance attempts targeting this specific function.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-85200. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation