CyberRota Analysis
AI-GeneratedThe WP Maps plugin for WordPress versions prior to 4.9.7 is vulnerable due to a lack of capability checks in its AJAX actions, enabling users with Subscriber accounts to include and execute arbitrary local PHP files on the server. This vulnerability poses a significant risk as it could lead to unauthorized code execution, potentially compromising the integrity of the affected WordPress site. WordPress administrators, particularly those using the WP Maps plugin, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.