CVE-2026-8386

MEDIUM NUCLEI

WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-8386 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

Nuclei Templates (1)

WP Go Maps < 10.0.10 - Unauthenticated Marker Information Disclosure
MEDIUMby 0x_Akoko
FOFA: body="/wp-content/plugins/wp-google-maps/"

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/fa7f5cb0-abe2-4079-9290-e0e4dc89f27f/

Scores

CVSS v3 5.3
EPSS 0.0070
EPSS Percentile 49.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

Status published
Products (1)
None/WP Go Maps < 10.0.10
Published Jun 15, 2026
Tracked Since Jun 15, 2026