CVE-2026-28144
Received Received - Intake

Sensitive Data Exposure in WP Maps Plugin

Vulnerability report for CVE-2026-28144, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: Patchstack

Description

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a through 4.9.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
patchstack wp_maps to 4.9.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves sensitive information being embedded in data sent by the WP Maps plugin for WordPress. It affects versions up to 4.9.6 and could allow unauthorized retrieval of this data.

Detection Guidance

Detection methods for this vulnerability are not specified in the provided CVE details. Reviewing the plugin's code for exposed sensitive data in embedded outputs and checking for unauthorized data retrieval in WP Maps versions up to 4.9.6 is recommended.

Impact Analysis

An attacker with access could retrieve sensitive data embedded in the plugin's communications. This may include user data or other confidential information transmitted by the plugin.

Compliance Impact

The vulnerability allows sensitive information to be embedded and retrieved from sent data, which could lead to unauthorized exposure of personal or confidential data. This may violate GDPR's data protection principles or HIPAA's safeguards for protected health information if such data is involved.

Mitigation Strategies

Update WP Maps to the latest version beyond 4.9.6 to address the vulnerability. If an update is not available, consider disabling or removing the plugin until a patch is released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-28144. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart