PT-2026-68872 · WordPress · Wp Amaps
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Maps versions prior to 4.9.7
Description
An issue exists where the plugin fails to perform a capability check in an AJAX action and does not properly validate a user-controlled path used in a file inclusion. This allows users with a Subscriber account to include and execute arbitrary existing local PHP files on the server. Local File Inclusion (LFI) is a vulnerability that allows an attacker to read or execute files on the server by manipulating file paths.
Recommendations
Update WP Maps to version 4.9.7 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Amaps