Description
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Published: 2026-08-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an unauthenticated Remote File Inclusion flaw in the Easy Google Maps plugin for WordPress. An attacker can supply a URL or path to a remote file, causing the plugin to fetch and execute that file within the context of the website. The plugin fails to validate or sanitize the file input, which can lead to execution of arbitrary code, compromising confidentiality, integrity, and availability.

Affected Systems

The affected system is the Easy Google Maps plugin from Supsystic. Versions prior to 1.14.2 are vulnerable. Site owners running an older version of the plugin on a WordPress installation are at risk.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw without authentication by sending a crafted request to the plugin. Successful exploitation may allow execution of arbitrary code within the website context.

Generated by OpenCVE AI on August 18, 2026 at 17:01 UTC.

Remediation

Vendor Solution

Update the WordPress Easy Google Maps Plugin to the latest available version (at least 1.14.2).


OpenCVE Recommended Actions

  • Update the Easy Google Maps plugin to version 1.14.2 or later, which removes the Remote File Inclusion flaw.
  • If the plugin is not required, uninstall it completely to eliminate the attack surface.
  • Apply secure file permissions on the WordPress upload directory so only trusted files can be served.
  • Enable logging of authentication failures and file inclusion attempts to detect potential exploitation attempts.

Generated by OpenCVE AI on August 18, 2026 at 17:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Supsystic
Supsystic easy Google Maps
Wordpress
Wordpress wordpress
Vendors & Products Supsystic
Supsystic easy Google Maps
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Title WordPress Easy Google Maps plugin < 1.14.2 - Remote File Inclusion vulnerability
Weaknesses CWE-829
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Supsystic Easy Google Maps
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:20.165Z

Reserved: 2026-08-12T10:51:25.492Z

Link: CVE-2026-73367

cve-icon Vulnrichment

Updated: 2026-08-18T19:39:24.235Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:05.123

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T17:15:04Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere