A critical unauthenticated PHP Object Injection vulnerability has been identified in the Geo Controller WordPress plugin affecting versions 8.9.8 and below. The vulnerability allows unauthenticated attackers to inject PHP objects, potentially leading to remote code execution or other severe impacts depending on available POP chains in the environment. The flaw is documented under CVE-2026-78286 and has been reported via both the NVD and Patchstack vulnerability databases. No authentication is required to exploit this vulnerability, significantly increasing its risk exposure. WordPress site administrators using the Geo Controller plugin (cf-geoplugin) should update to a patched version immediately. The vulnerability was flagged with a high criticality rating. Patchstack has published additional details and patch information for affected users.