CVE-2026-18465
WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.
| Vendor | unknown |
| Product | wp maps pro |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp maps pro
Be the first to know when new unknown vulnerabilities affecting unknown wp maps pro are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP MAPS PRO
0 < 6.1.3
References
Credits
Jakub Herman WPScan