CVE-2026-18465 PUBLISHED

WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion

Assigner: WPScan
Reserved: 31.07.2026 Published: 09.08.2026 Updated: 09.08.2026

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.

Product Status

Vendor Unknown
Product WP MAPS PRO
Versions Default: unaffected
  • affected from 0 to 6.1.3 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE