The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
History

Fri, 07 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-284

Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Maps
Wp Maps wp Maps
Vendors & Products Wordpress
Wordpress wordpress
Wp Maps
Wp Maps wp Maps

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
Title WP Maps < 4.9.7 - Subscriber+ Local File Inclusion
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T06:00:14.183Z

Reserved: 2026-07-20T08:40:38.798Z

Link: CVE-2026-16263

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T08:00:06Z