Junglewise Threat Intelligence

CVE-2026-28144: Flipper Code WP Maps sensitive data exposure

CVE-2026-28144 · Severity: medium · CVSS 4.3 · Published 2026-07-31

Executive brief

Flipper Code WP Maps, a WordPress plugin used to embed interactive maps on websites, contains a security flaw that can expose sensitive information. An authenticated user with low-level access, such as a subscriber, could potentially view data that is intended to be restricted. This exposure could lead to further unauthorized access or assist in more complex attacks against the website.

Technical details

The WP Maps plugin (formerly WP Google Map Plugin) for WordPress is vulnerable to a sensitive data exposure flaw (CWE-201) in versions up to and including 4.9.6. The vulnerability arises when the application includes sensitive information in data sent to the client-side, which can then be retrieved by an attacker. Exploitation requires 'Subscriber' level authentication or higher. An attacker can leverage this to access embedded sensitive data that is not intended for public or low-privileged viewing. The issue is addressed in version 4.9.7.

Affected products

  • Flipper Code WP Maps up to 4.9.6

Timeline

  • 2026-07-16: other: Reported by researcher
  • 2026-07-31: advisory: Published by Patchstack and NVD
  • 2026-07-31: patched: Version 4.9.7 released to address the issue

References