The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The WP Maps plugin for WordPress contains a Local File Inclusion (LFI) vulnerability in the 'page' parameter that allows authenticated attackers with subscriber-level privileges to include and execute arbitrary PHP files on the server. This vulnerability (CVE-2026-13456, CVSS 7.5) is particularly dangerous because it requires only low-level authenticated access—a common attack vector when subscriber accounts are compromised or created by threat actors. The ability to execute arbitrary PHP code enables attackers to bypass access controls, exfiltrate sensitive data, establish persistent backdoors, or pivot laterally within the WordPress installation and underlying infrastructure. Any organization running versions 4.9.8 or earlier of this popular mapping plugin is exposed to these post-authentication code execution risks.
While this CVE currently maps to zero Casky.ai skills and no MITRE ATT&CK techniques in the CVE record, practitioners using Casky's Claude AI-powered analysis would identify the underlying attack patterns through behavioral detection. The plugin's improper input validation on the 'page' parameter represents a classic example of Improper Neutralization of Special Elements (CWE-98), which Casky's 754 security skills can correlate across multiple detection vectors: abnormal file path traversal patterns in application logs, unexpected PHP file access through web parameters, authentication followed by suspicious include() or require() function calls in code analysis, and post-authentication execution flows that deviate from normal plugin behavior. Security practitioners would see findings flagging the chain from initial authentication → parameter manipulation → file system traversal → code execution, enabling them to detect compromise attempts before successful exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-13456. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation