PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18465 WP MAPS PRO CVE debrief

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.

Vendor
WP MAPS PRO
Product
WP MAPS PRO WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-09
Original CVE updated
2026-08-09
Advisory published
2026-08-09
Advisory updated
2026-08-09

Who should care

Users of the WP MAPS PRO WordPress plugin, particularly those responsible for maintaining and securing WordPress installations, should be aware of this vulnerability. They should verify their plugin version and update to 6.1.3 or later to mitigate this vulnerability. Additionally, security teams and vulnerability management teams should review the affected scope and severity to determine the appropriate course of action. Operators and platform administrators should also be aware of the potential impact on their systems and take necessary precautions. This vulnerability could have significant operational impact if exploited, and defenders should take steps to verify and mitigate it promptly. Compensating controls, such as monitoring and asset inventory, may be necessary while remediation is scheduled and verified. The vulnerability management team should track exceptions and retest remediated assets to ensure that the vulnerability is properly mitigated. The security team should review compensating controls for exposed systems while remediation is scheduled and verified. The operator should check relevant monitoring, detection, and logs for exposed assets that need extra review. The platform administrator should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. The vulnerability management team should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also track exceptions, retest remediated assets, and close the item only after evidence is documented. The security team should review compensating controls for exposed systems while remediation is scheduled and verified. The operator should check relevant monitoring, detection, and logs for exposed assets that need extra review. The platform administrator should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. They should also confirm whether affected product deployments exist in managed environments and assign a

Technical summary

The WP MAPS PRO WordPress plugin before version 6.1.3 is vulnerable to arbitrary file inclusion due to a lack of capability checks and path validation in one of its AJAX actions. This vulnerability could allow unauthenticated attackers to include and execute arbitrary existing local PHP files on the server. Users of the plugin should verify their version and update to 6.1.3 or later to mitigate this vulnerability.

Defensive priority

Organizations using the WP MAPS PRO WordPress plugin should verify their version and update to 6.1.3 or later to mitigate this vulnerability.

Recommended defensive actions

  • Verify WP MAPS PRO plugin version
  • Update to version 6.1.3 or later
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The evidence for this CVE is limited. The WP MAPS PRO WordPress plugin before version 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users. This could allow unauthenticated attackers to include and execute arbitrary existing local PHP files on the server. Defenders should verify the plugin version and user authentication mechanisms. Additional verification is needed to confirm affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T06:19:05.653Z and has not been modified since then.