{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cm-map-locations-2.1.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-16601"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CM Map Locations (2.1.8)"],"_cs_severities":["high"],"_cs_tags":["wordpress","arbitrary-file-upload","remote-code-execution","plugin-vulnerability"],"_cs_type":"advisory","_cs_vendors":["CreativeMinds"],"content_html":"\u003cp\u003eThe CM Map Locations plugin for WordPress (up to version 2.1.8) contains a critical security flaw involving the improper handling of file uploads in the uploadMedia function. The plugin fails to perform adequate file type validation or MIME-type checking, allowing authenticated users with subscriber-level access to bypass extension filtering.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is exacerbated by the exposure of a required security nonce within the CMLOC_Editor_Images JavaScript object on the front-end location editor page. By obtaining this nonce, an authenticated subscriber can craft requests that bypass intended permission checks, leading to the upload of executable files to the server. Successful exploitation allows for remote code execution, posing a significant risk to site integrity and server security. Defenders should prioritize updating to the patched version of the plugin and auditing logs for unusual file uploads to the plugin media directories.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates as a user with subscriber-level privileges on the WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the front-end location editor page provided by the CM Map Locations plugin.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the required security nonce from the CMLOC_Editor_Images JavaScript object.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a POST request to the uploadMedia handler using the extracted nonce.\u003c/li\u003e\n\u003cli\u003eAttacker includes a malicious payload (e.g., a PHP script) within the file upload request.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to validate the file extension or MIME-type, passing the file to move_uploaded_file().\u003c/li\u003e\n\u003cli\u003eThe malicious file is written to the web-accessible file system.\u003c/li\u003e\n\u003cli\u003eAttacker requests the uploaded file directly via the browser to trigger remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unprivileged authenticated user to gain remote code execution on the WordPress server. This could lead to full site compromise, exfiltration of database contents, or use of the host server for further network attacks. Because the plugin is a common mapping solution, the potential blast radius includes any WordPress instance running version 2.1.8 or lower.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the CM Map Locations plugin to the latest version immediately to remediate the vulnerable uploadMedia function.\u003c/li\u003e\n\u003cli\u003eAudit the webserver access logs for anomalous POST requests to the plugin upload endpoints, specifically targeting non-image file extensions or suspicious file paths.\u003c/li\u003e\n\u003cli\u003eReview WordPress user roles to ensure that subscriber accounts are necessary and do not have access to sensitive front-end editing features where these scripts are exposed.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring on the WordPress uploads directory to detect unauthorized file creation by the web service user.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T10:07:27Z","date_published":"2026-08-25T10:07:27Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cm-map-locations-rce/","summary":"The CM Map Locations WordPress plugin is vulnerable to remote code execution due to insufficient file validation in the uploadMedia function, allowing subscriber-level authenticated users to upload arbitrary executable files.","title":"Arbitrary File Upload in CM Map Locations WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cm-map-locations-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - CM Map Locations (2.1.8)","version":"https://jsonfeed.org/version/1.1"}