CVE-2026-28144: WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data.
This issue affects WP Maps: from n/a through 4.9.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Maps pluginto a version that resolves this vulnerability.Fixed in 4.9.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28144?
CVE-2026-28144 has a medium severity rating of 4.3.
What type of vulnerability is described in CVE-2026-28144?
CVE-2026-28144 is a Sensitive Data Exposure vulnerability affecting the WordPress WP Maps plugin.
How does CVE-2026-28144 affect the WP Maps plugin?
CVE-2026-28144 allows for the retrieval of embedded sensitive data due to the insertion of sensitive information into sent data.
What versions of WP Maps are affected by CVE-2026-28144?
CVE-2026-28144 affects WP Maps versions from n/a up to and including 4.9.6.
How can I mitigate the risks associated with CVE-2026-28144?
To mitigate the risks of CVE-2026-28144, it is recommended to update the WP Maps plugin to the latest version to address the vulnerability.