Unauthenticated Remote File Inclusion in Easy Google Maps by Easy Google Maps
CVE-2026-73367

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 August 2026

What is CVE-2026-73367?

An unauthenticated remote file inclusion vulnerability exists in the Easy Google Maps plugin for WordPress, specifically affecting versions prior to 1.14.2. This vulnerability allows an attacker to exploit the application by including remote files, potentially compromising the host server and gaining unauthorized access. It is crucial for website administrators to update the plugin to a secure version or apply necessary mitigations to safeguard against this exploit.

Affected Version(s)

Easy Google Maps < 1.14.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Asim Alshaya | Patchstack Bug Bounty Program
.