Security Advisory

CVE-2026-6381

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-18 06:00:08
Last updated 2026-05-18 13:37:39
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.