Local File Inclusion in WP Maps Plugin for WordPress
CVE-2026-13456

7.5HIGH

What is CVE-2026-13456?

The WP Maps plugin for WordPress is susceptible to a Local File Inclusion vulnerability in all versions up to and including 4.9.8. This flaw allows authenticated attackers with subscriber-level access or higher to exploit the 'page' parameter, enabling them to include and execute arbitrary PHP files stored on the server. Such unauthorized access can lead to the execution of malicious PHP code, potential bypass of access controls, data exposure, and further exploitation, underscoring the need for immediate mitigation and updates.

Affected Version(s)

WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings 0 <= 4.9.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

lhking
.