PatchSiren

flippercode CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH flippercode CVE published 2026-09-25

CVE-2026-13456

The WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator, Listing, Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8. Authenticated attackers with subscriber-level access and above can include and execute arbitrary .php files on the server, allowing PHP code execution. This can be used to bypass access controls, obtain sensiti [truncated]

MEDIUM flippercode CVE published 2026-09-25

CVE-2026-13179

The WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator, Listing, Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shapes_values parameter in all versions up to, and including, 4.9.8. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesse [truncated]