CVE-2026-6381: WP Maps < 4.9.3 - Subscriber+ Local File Inclusion
Published May 18, 2026
·Updated
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
Affected Software
1 affected component
WP Maps<4.9.3
Event History
May 18, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-6381?
CVE-2026-6381 is classified as a high severity vulnerability due to its potential for Local File Inclusion attacks.
2
How do I fix CVE-2026-6381?
To fix CVE-2026-6381, upgrade the WP Maps plugin to version 4.9.3 or later.
3
Who is affected by CVE-2026-6381?
Authenticated users of the WP Maps plugin versions prior to 4.9.3 are affected by CVE-2026-6381.
4
What type of attacks can CVE-2026-6381 facilitate?
CVE-2026-6381 can facilitate Local File Inclusion attacks, potentially exposing sensitive files.
5
Is authentication required to exploit CVE-2026-6381?
Yes, authentication is required to exploit CVE-2026-6381, as it affects authenticated users.