HIGHCVE-2026-6381Published Modified CNA WPScan
CVE-2026-6381: WP Maps < 4.9.3 - Subscriber+ Local File Inclusion
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- 4.9.3
- Affected Products
- 1
Fix available
4.9.3
Affected packages
- Unknown / WP Maps< 4.9.3 (from 0)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HReferences