CVE-2026-6381: Unknown Wp Maps
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
Affected products
- Unknown Wp Maps: before 4.9.3 (fixed in 4.9.3)
Published 2026-05-18. Last modified 2026-06-17.