AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16263

HIGH · CVSS 8.8 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Maps plugin for WordPress versions prior to 4.9.7 is vulnerable due to a lack of capability checks in its AJAX actions, enabling users with Subscriber accounts to include and execute arbitrary local PHP files on the server. This vulnerability poses a significant risk as it could lead to unauthorized code execution, potentially compromising the integrity of the affected WordPress site. WordPress administrators, particularly those using the WP Maps plugin, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16263
Severity
HIGH
CVSS
8.8
EPSS
0.34%
WordPress

Original NVD Description

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.