CVE

CVE-2026-16263 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-16263 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 4.9.7 4.9.7 2026-08-03

CVE-2026-16263

A vulnerability exists in WP Maps plugin versions prior to 4.9.7 due to inadequate security checks in an AJAX action. This oversight allows malicious users with even basic privileges to access and run any locally available PHP scripts, bypassing intended access controls. The issue can be exploited by a user with a Subscriber account.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.