CVE-2026-73366: WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Affected Software
1 affected component
WordPress Easy Google Maps plugin<=1.13.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Easy Google Maps pluginto a version that resolves this vulnerability.Fixed in 1.14.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be treated as exposed?
Sites running Easy Google Maps version 1.13.0 or earlier are affected. The issue is in the WordPress plugin, so exposure depends on whether that plugin is installed and active.
2
Does exploitation require an account or user action?
The vulnerability is unauthenticated and requires no user interaction, according to the supplied severity vector. An attacker can exploit it remotely without WordPress credentials.