Local File Inclusion in WP Maps Plugin for WordPress
CVE-2026-13456
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-13456?
The WP Maps plugin for WordPress is susceptible to a Local File Inclusion vulnerability in all versions up to and including 4.9.8. This flaw allows authenticated attackers with subscriber-level access or higher to exploit the 'page' parameter, enabling them to include and execute arbitrary PHP files stored on the server. Such unauthorized access can lead to the execution of malicious PHP code, potential bypass of access controls, data exposure, and further exploitation, underscoring the need for immediate mitigation and updates.
Affected Version(s)
WP Maps β Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings 0 <= 4.9.8