PT-2026-98382 · WordPress · Wp Amaps

·

CVE-2026-13456

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters versions prior to 4.9.9
Description Local File Inclusion occurs via the page parameter. Authenticated attackers with subscriber-level access or higher can include and execute arbitrary .php files on the server. This allows for the execution of PHP code contained within those files, which can be used to bypass access controls, obtain sensitive data, or achieve remote code execution if .php files can be uploaded to the server.
Recommendations Update the plugin to version 4.9.9 or later. Avoid using the page parameter in the affected plugin until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13456

Affected Products

Wp Amaps