We are informing all Geo Controller users about a security vulnerability affecting plugin versions up to and including 8.9.8.
The vulnerability is tracked as CVE-2026-78286 and affects Geo Controller versions up to and including 8.9.8. The issue is resolved in version 8.9.9.
The vulnerability was publicly disclosed by Patchstack as a high-priority PHP Object Injection issue. The problem has been fixed in Geo Controller version 8.9.9, which was made available before the public Patchstack disclosure.
Who Is Affected?
The following versions are affected:
- Geo Controller 8.9.8 and all earlier versions
The vulnerability is fixed in:
- Geo Controller 8.9.9
If your website is already running version 8.9.9 or newer, it includes the security fix.
What Should Users Do?
All users running Geo Controller 8.9.8 or an earlier version should update the plugin immediately.
To check your installed version:
- Open your WordPress administration area.
- Navigate to Plugins > Installed Plugins.
- Locate Geo Controller.
- Confirm that version 8.9.9 or newer is installed.
You can update Geo Controller directly from the WordPress Plugins screen or download the latest version from the official WordPress Plugin Directory.
Download Geo Controller from WordPress.org
About the Security Fix
Geo Controller 8.9.9 introduces stricter validation and safer data handling in the affected plugin components. The update also improves authorization checks and strengthens the handling of data used by plugin integrations and SEO redirection tools.
Technical exploitation details are intentionally not included in this announcement to reduce the risk of misuse against websites that have not yet been updated.
The vulnerability has been publicly documented by Patchstack:
View the Patchstack security advisory
Our Commitment to Security
Security reports are taken seriously and addressed as quickly as possible. The fix was prepared and released in version 8.9.9 before the vulnerability became publicly available in the Patchstack database.
We strongly recommend keeping Geo Controller, WordPress, themes and all other plugins updated. Regular updates remain one of the most effective ways to protect a WordPress website from known vulnerabilities.
If you have questions about this update or need help confirming your plugin version, please contact our support team.
Contact Geo Controller Support
Thank you for using Geo Controller and for keeping your WordPress website updated.

