Vulnerability Description
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a Subscriber account to include and execute arbitrary existing local PHP files on the server.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-16263?
CVE-2026-16263 is a vulnerability with a CVSS score of 8.8 (HIGH). The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, all...
How severe is CVE-2026-16263?
CVE-2026-16263 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-16263?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.