CVE Database /
CVE-2025-12062
CVE · High
CVE-2025-12062 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-12062
|
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
8.8
|
< 4.8.7
|
4.8.7 |
2026-02-16 |
—
|
CVE-2025-12062
The WP Maps plugin for WordPress contains a security flaw that allows attackers with Subscriber-level access or higher to inject arbitrary server-side code by exploiting the fc_load_template function in versions up to 4.8.6. This vulnerability enables malicious users to bypass access restrictions, potentially extract sensitive information, and execute PHP code contained within specific types of uploaded files.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings