Security Alert Summary
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion (LFI) attacks. This can let an attacker access local files on the server that should not be exposed.
CVE Details
- CVE ID: CVE-2026-6381
- Affected component: WP Maps WordPress plugin
- Affected versions: Versions before 4.9.3
- Published: May 18, 2026 at 7:16:12 AM UTC
- Last modified: May 18, 2026 at 3:16:26 PM UTC
- CVSS v3.1 base score: 7.5 (HIGH)
- CVSS vector:
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - Authentication / privileges / user interaction: Authentication required; low privileges (PR:L); no user interaction (UI:N)
- Primary impact: Confidentiality: High; Integrity: High; Availability: High
- Weakness: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory, aka Path Traversal)
Technical Details
The plugin fails to properly sanitize a parameter before using it in a file path. By supplying crafted input that manipulates the file path, an authenticated user can trigger a Local File Inclusion (LFI) condition that causes the application to read files from the local filesystem that were not intended to be exposed.
This vulnerability exists because user-supplied input is used directly in a file path operation without adequate validation or normalization. The CVE description identifies the issue as an LFI that arises from improper sanitization; no specific functions or REST endpoints are named in the provided data.
Impact is limited to reading local files accessible by the web server process. The attacker ability to read sensitive files depends on file permissions and server configuration. The provided CVSS metrics indicate a network-accessible issue with high impact to confidentiality, integrity, and availability when exploited by an authenticated user with low privileges.
How This Could Impact Your Website
Consider a small site where the site owner manages plugins, an internal staff member (editor or content manager) handles posts, and an external contractor contributes content. If an authenticated contributor or contractor can exploit this LFI, they may be able to access local files that contain configuration or user data. Practical consequences include exposure of internal user email addresses or other sensitive files stored on the server, which could increase the risk of targeted phishing or social engineering against staff or contributors.
While LFI does not automatically mean full site takeover, reading sensitive files can disclose configuration details and credentials that raise the risk of further attacks. If you're unsure whether your site is affected or how to assess your current user roles and plugins, it may be worth having a professional review.
Recommended Actions
- Update the affected plugin as soon as a patched version is available.
- Review and reduce unnecessary user roles, especially contributor-level accounts and other low-privilege authenticated users.
- Enforce strong passwords and enable two-factor authentication for editors and administrators.
- Remove unused or unmaintained plugins from your site.
- Monitor site activity and server logs for unusual behavior or unexpected file access attempts.
If you'd like help reviewing your plugins, user roles, or overall WordPress security posture, our team at Freshy is happy to help.