9.8
CVE-2026-78286
- EPSS 0.53%
- Veröffentlicht 27.08.2026 09:00:02
- Zuletzt bearbeitet 28.08.2026 20:19:57
- Erkennungen
WordPress Geo Controller plugin <= 8.9.8 - PHP Object Injection vulnerability
Geo Controller <= 8.9.8 - Unauthenticated PHP Object Injection
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Mögliche Gegenmaßnahme
Geo Controller: Update to version 8.9.9, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerINFINITUM FORM
≫
Produkt
Geo Controller
Default Statusunaffected
Version <=
8.9.8
Version
n/a
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Geo Controller
Version
*-8.9.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.423 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://patchstack.com/database/wordpress/plugin/cf-geoplugin/vulnerability/wordpress-geo-controller-plugin-8-9-8-php-object-injection-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/d7c9ef25-dc57-4a38-84d6-40f38bf96e4e