HomeDefault status
unaffected
Any version before 4.9.3
affected
Description
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version before 4.9.3
Credits
Mustafa Ahmed
WPScan
References
wpscan.com/...rability/18b36672-58d7-44fa-b653-b728e9ef257a/