Product
The CM Map Locations WordPress plugin is vulnerable to remote code execution due to insufficient file validation in the uploadMedia function, allowing subscriber-level authenticated users to upload arbitrary executable files.