Description
Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated PHP Object Injection exists in the Easy Google Maps plugin versions up to and including 1.13.0. The flaw allows an attacker to craft a specially crafted HTTP request that is deserialized by the plugin’s PHP code, enabling the attacker to instantiate arbitrary objects and potentially execute arbitrary code on the host server. This results in complete compromise of the affected web application, allowing disclosure, modification, or deletion of data and execution of commands on the underlying system.

Affected Systems

The vulnerability affects the Easy Google Maps plugin developed by Supsystic, specifically all releases with version numbers 1.13.0 or earlier. WordPress sites that have not upgraded beyond 1.13.0 are susceptible, regardless of other plugins or themes. No additional systems or extensions are listed as affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score is not available, and the vulnerability is not yet listed in the CISA KEV catalog. No details on required conditions are provided, so the likely attack vector is inferred to be unauthenticated HTTP requests targeting the plugin’s endpoints, with no authentication or privilege escalation needed. Given the high severity, the risk of exploitation is substantial for sites that have not applied the available patch.

Generated by OpenCVE AI on August 18, 2026 at 16:17 UTC.

Remediation

Vendor Solution

Update the WordPress Easy Google Maps Plugin to the latest available version (at least 1.14.0).


OpenCVE Recommended Actions

  • Update the Easy Google Maps plugin to the latest available version (at least 1.14.0).
  • If a plugin upgrade is not immediately possible, temporarily disable or remove the Easy Google Maps plugin to eliminate the entry point.
  • Continuously monitor web application logs for suspicious activity that could indicate attempts to exploit object injection.

Generated by OpenCVE AI on August 18, 2026 at 16:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.
Title WordPress Easy Google Maps plugin <= 1.13.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T14:38:24.758Z

Reserved: 2026-08-12T10:51:25.492Z

Link: CVE-2026-73366

cve-icon Vulnrichment

Updated: 2026-08-18T14:38:21.949Z

cve-icon NVD

Status : Received

Published: 2026-08-18T15:17:04.960

Modified: 2026-08-18T15:17:04.960

Link: CVE-2026-73366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:30:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data