---
id: CVE-2026-18465
title: >-
  The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability
  check in one of its AJAX actions, which is also available to unauthenticated
  users, and does not properly validate a user-controlled path before using it
  in a fi…
summary: >-
  The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability
  check in one of its AJAX actions, which is also available to unauthenticated
  users, and does not properly validate a user-controlled path before using it
  in a fi…
severity: none
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18465'
references:
  - url: 'https://wpscan.com/vulnerability/53da3a6d-1eab-4f61-ba61-fa7a04d2205a/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00337
epssPercentile: 0.24306
ingestedAt: '2026-08-09T15:33:38.356Z'
---

## Overview

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not properly validate a user-controlled path before using it in a file inclusion, allowing unauthenticated attackers to include and execute arbitrary existing local PHP files on the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
