CVE-2026-1730

OS DataHub Maps <= 1.8.3 - Authenticated (Author+) Arbitrary File Upload

The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.


We have discovered 317 live websites that are affected by CVE-2026-1730.

Run a Free Instant Scan




Affected Software

Product  Os Datahub Maps
Category Wordpress Plugins
Vulnerable Domains317 live websites (100% of Os Datahub Maps install base)
Vulnerable Versions
  • from 0 through 1.8.3
Vulnerable Versions Count4 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Feb 3, 2026
  • Updated - Feb 3, 2026

Credits

  • Williwollo (finder)

Website Distribution by Country

Number of websites using CVE-2026-1730
United States89 websites



GB213 websites
Germany6 websites
Denmark2 websites
France2 websites
Bulgaria1 websites
Canada1 websites
Estonia1 websites
Hong Kong1 websites
Luxembourg1 websites

Website Distribution by TLD

Number of websites using CVE-2026-1730
.org.uk121 websites
.co.uk75 websites
.org55 websites
.com44 websites
.net4 websites
.info1 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1730

Top websites that are affected by CVE-2026-1730. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com GB**,***
*************.**.uk GB***,***
***********.org GB***,***
********.**.uk GB***,***
**********************.**.uk United States***,***
****************.***.uk United States*,***,***
****************.**.uk GB*,***,***
***********.***.uk GB*,***,***
************.org United States*,***,***
**************.**.uk GB*,***,***
See full domain list

FAQ

CVE-2026-1730 is Unrestricted Upload of File with Dangerous Type in Os Datahub Maps
A total of 317 websites have been identified as vulnerable to CVE-2026-1730, based on global website indexing conducted by WebTechSurvey.
The Os Datahub Maps is affected by the CVE-2026-1730 vulnerability.
Os Datahub Maps versions up to and including 1.8.3 are vulnerable to CVE-2026-1730.