7.2

CVE-2026-73367

WordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerability

Easy Google Maps < 1.14.2 - Unauthenticated Arbitrary Remote Script Inclusion

Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Mögliche Gegenmaßnahme
Easy Google Maps: Update to version 1.14.2, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellersupsystic
≫
Produkt Easy Google Maps
Default Statusunaffected
Version n/a
Version < 1.14.2
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt Easy Google Maps
Version [*, 1.14.2)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.164
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
audit@patchstack.com 7.2 3.9 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

https://patchstack.com/database/wordpress/plugin/google-maps-easy/vulnerability/wordpress-easy-google-maps-plugin-1-14-2-remote-file-inclusion-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/d1167f98-850c-4493-b93e-95e59bfe7df7
Third Party Advisory