CVE-2026-8386
MEDIUM NUCLEIWP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID
Title source: cnaExploitation Summary
CVE-2026-8386 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.
Nuclei Templates (1)
WP Go Maps < 10.0.10 - Unauthenticated Marker Information Disclosure
MEDIUMby 0x_Akoko
FOFA:
body="/wp-content/plugins/wp-google-maps/"
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/fa7f5cb0-abe2-4079-9290-e0e4dc89f27f/
Scores
CVSS v3
5.3
EPSS
0.0070
EPSS Percentile
49.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
Status
published
Products (1)
None/WP Go Maps
< 10.0.10
Published
Jun 15, 2026
Tracked Since
Jun 15, 2026