{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awp_mapswp_mapswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp_maps:wp_maps:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-13456"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory \u0026 Filters (\u003c= 4.9.8)"],"_cs_severities":["high"],"_cs_tags":["web-application","vulnerability","lfi"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Maps WordPress plugin, specifically versions 4.9.8 and earlier, contains a critical security flaw categorized as Local File Inclusion (LFI). This vulnerability resides in the 'page' parameter and is accessible to any user with subscriber-level permissions or higher. An attacker can manipulate this parameter to point to arbitrary files stored on the server. If the attacker can upload a file containing malicious PHP code or leverage existing files on the host, they can force the server to execute that code. This vulnerability poses a significant risk to the integrity and confidentiality of the host environment, as it allows for bypass of application-level access controls and potential remote code execution. Defenders should prioritize updating to a patched version or auditing plugin usage to restrict access to the affected functionality.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid subscriber-level credentials for a WordPress site running the vulnerable plugin.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the WordPress dashboard and navigates to the endpoint utilizing the WP Maps plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET or POST request targeting the parameter 'page'.\u003c/li\u003e\n\u003cli\u003eAttacker injects a path traversal or local file path into the 'page' parameter to target a specific file on the server filesystem.\u003c/li\u003e\n\u003cli\u003eThe plugin code fails to validate or sanitize the 'page' parameter input.\u003c/li\u003e\n\u003cli\u003eThe PHP include function processes the path, triggering the execution of the targeted .php file.\u003c/li\u003e\n\u003cli\u003eMalicious code within the included file executes with the privileges of the web server user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers with low-level privileges to gain unauthorized access to sensitive server data, bypass authentication mechanisms, or achieve remote code execution. This can lead to full compromise of the web application and the underlying server environment, depending on the server's configuration and file permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WP Maps plugin to the latest version immediately to remediate CVE-2026-13456.\u003c/li\u003e\n\u003cli\u003eAudit access logs for suspicious HTTP requests containing directory traversal sequences (e.g., ../) within the 'page' parameter.\u003c/li\u003e\n\u003cli\u003eEnforce strict input validation on all plugins to prevent arbitrary file path inclusion.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected file uploads to directories that the web server can read or execute.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T08:55:57Z","date_published":"2026-09-25T08:55:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-maps-lfi/","summary":"An authenticated local file inclusion vulnerability in the WP Maps plugin allows subscribers to execute arbitrary PHP files on WordPress servers via the page parameter.","title":"Local File Inclusion Vulnerability in WP Maps Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-maps-lfi/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wp_maps:wp_maps:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}