What is CVE-2026-18465?
The WP MAPS PRO WordPress plugin before version 6.1.3 has an AJAX action accessible to unauthenticated users due to a missing capability check, combined with improper validation of a user-controlled path used in a file inclusion. This vulnerability allows unauthenticated attackers to perform Local File Inclusion (LFI), potentially leading to remote code execution, and updating to the latest version is strongly recommended.
Azərbaycanca: WP MAPS PRO WordPress plaginində (6.1.3-dən əvvəlki versiyalarda) autentifikasiya olunmamış istifadəçilərə imkan verən AJAX əməliyyatında düzgün icazə yoxlaması və fayl yolu doğrulaması çatışmazlığı mövcuddur. Bu boşluq uzaqdan kod icrasına səbəb ola biləcək Local File Inclusion (LFI) hücumuna şərait yaradır, plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
What versions of the WP MAPS PRO plugin are affected by CVE-2026-18465 and what can exploitation lead to?
The vulnerability affects WP MAPS PRO versions before 6.1.3. Exploitation can lead to unauthenticated Local File Inclusion (LFI), which may result in remote code execution.
What is recommended to protect against CVE-2026-18465?
It is strongly recommended to update the plugin to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.