CVE-2026-18466: WP Maps < 4.9.8 - Subscriber+ Unlimited Autoloaded Option Creation

Published Aug 19, 2026
·
Updated

The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.

Affected Software

1 affected component
WordPress plugin WP Maps<4.9.8

Event History

Aug 19, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated user with a Subscriber account can exploit the affected AJAX action. This does not require administrative privileges.

2

What is the likely impact of exploitation?

An attacker can create an unlimited number of database options that are autoloaded on every page request. This can increase per-request database and memory overhead and may degrade site performance or availability.

3

Which plugin versions are affected?

WP Maps versions before 4.9.8 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203