PT-2026-69275 · WordPress · Wp Maps Pro
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP MAPS PRO versions prior to 6.1.3
Description
An issue exists where a capability check is missing in an AJAX action available to unauthenticated users. The plugin fails to properly validate a user-controlled path used in a file inclusion process, which allows unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.
Recommendations
Update WP MAPS PRO to version 6.1.3 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Maps Pro