CVE-2025-12062Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary .html files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .html file types can be uploaded and included.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-17); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-16: 1Mentions · 2026-02-17: 4Mentions · 2026-02-22: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 3Technical Details · 2026-02-22: 102-1602-1702-22
Signal classification1 categories
Disclosure
6100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-161
Disclosure1
2026-02-174
Disclosure4
2026-02-221
Disclosure1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-12062 Local File Inclusion in WP Maps WordPress Plugin via fc_load_template Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-12062

    Post summary

    The text reports the disclosure of CVE‑2025‑12062, a local file inclusion flaw in the WP Maps WordPress plugin through the fc_load_template function. No proof‑of‑concept, exploit, active exploitation, patch, or false‑positive claim is provided.

    1001062
    4.0K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @VulmonFeeds 🚨 **CVE-2025-12062** is a **Local File Inclusion (LFI)** vulnerability in the **WP Maps – Store Locator, Google Maps, OpenStreetMap, Mapbox, Listing, Directory & Filters** WordPress plugin, affecting all versions up to and including **4.8.6**. #WordPress #LFI

    Post summary

    CVE-2025-12062 is a Local File Inclusion vulnerability affecting the WP Maps plugin up to version 4.8.6; no exploitation, patches, or false‑positive claims are mentioned.

    1000050
    313 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-12062 The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up… https://www.cve.org/CVERecord?id=CVE-2025-12062

    Post summary

    The text announces a local file inclusion vulnerability (CVE‑2025‑12062) in the WP Maps plugin, linking to its CVE record but providing no further exploitation or mitigation details.

    00010978
    56.4K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-12062 (CVSS:8.8, HIGH) is Awaiting Analysis. The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnera..https://nvd.nist.gov/vuln/detail/CVE-2025-12062 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-12062 is a high‑severity vulnerability in the WP Maps plugin, currently awaiting analysis, with no PoC, exploit, or patch details provided.

    0000042
    171 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-12062 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-12062 #CVE-2025-12062 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/F1cPYBo787

    Post summary

    The tweet announces a newly disclosed high‑severity WordPress vulnerability (CVE‑2025‑12062) and directs readers to the NVD for details.

    0000066
    56 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2025-12062 - High The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8... https://www.thehackerwire.com/vulnerability/CVE-2025-12062/ https://t.co/B9GLhw1LLi

    Post summary

    The tweet announces CVE‑2025‑12062, a Local File Inclusion vulnerability affecting WP Maps plugin versions up to 4.8. No PoC, exploit, or patch details are provided.

    0000065
    112 followersView on X

Explore more