What is CVE-2026-16263?
A vulnerability in the WP Maps WordPress plugin before version 4.9.7 allows Subscriber-level users to perform unauthorized local file inclusion. This occurs due to a missing capability check in an AJAX action, enabling execution of arbitrary PHP files. Users should update the plugin and enforce strict access controls.
Azərbaycanca: WP Maps WordPress plaginində (4.9.7-dən əvvəl) Subscriber roluna malik istifadəçilərin icazəsiz PHP faylı daxil etməsinə imkan verən zəiflik aşkar edilib. Bu, AJAX əməliyyatında səlahiyyət yoxlamasının aparılmaması səbəbindən baş verir. İstifadəçilər plaqini ən son versiyaya yeniləməli və giriş yoxlamalarını gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What level of account does an attacker need to exploit CVE-2026-16263 in the WP Maps plugin?
An attacker only needs a Subscriber-level user account, as there is a missing capability check in the AJAX action.
To which version should the WP Maps plugin be updated to protect against CVE-2026-16263?
The plugin should be updated to version 4.9.7 or later, as the vulnerability exists in versions before 4.9.7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.