CVE · High

CVE-2025-12062 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12062 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.8 < 4.8.7 4.8.7 2026-02-16

CVE-2025-12062

The WP Maps plugin for WordPress contains a security flaw that allows attackers with Subscriber-level access or higher to inject arbitrary server-side code by exploiting the fc_load_template function in versions up to 4.8.6. This vulnerability enables malicious users to bypass access restrictions, potentially extract sensitive information, and execute PHP code contained within specific types of uploaded files.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.