The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_revision function in all versions up to, and including, 2.8.169. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). By placing post_type=attachment exclusively in the query string to bypass the consistency check, an attacker can convert an auto-draft GeoDirectory listing into a WordPress attachment with attacker-controlled file paths injected into attachment metadata, which the delete_revision handler then dereferences and unlinks without any post-type or path validation.
We have discovered 2,941 live websites that are affected by CVE-2026-19091.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 2,941 live websites (100% of Geodirectory install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 162 versions ( 100% of all versions) |
| 1,332 websites | |
| 222 websites | |
| 217 websites | |
| 138 websites | |
| 104 websites | |
| 103 websites | |
| 95 websites | |
| 88 websites | |
| 66 websites | |
| 50 websites |
| .com | 1,358 websites |
| .org | 277 websites |
| .co.uk | 127 websites |
| .de | 119 websites |
| .net | 89 websites |
| .fr | 71 websites |
| .com.au | 68 websites |
| .ca | 66 websites |
| .it | 45 websites |
| .nl | 38 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.org | **,*** | ||
| *********.com | **,*** | ||
| ****.org | **,*** | ||
| ***************.com | **,*** | ||
| *****.org | **,*** | ||
| ******.com | ***,*** | ||
| ****************.com | ***,*** | ||
| *****.*******.io | ***,*** | ||
| ******.org | ***,*** | ||
| ****************.com | ***,*** |
FAQ