CVE-2026-73183: WordPress Maps Marker Pro plugin <= 4.32 - SQL Injection vulnerability
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Maps Marker Proto a version that resolves this vulnerability.Fixed in 4.32.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. The CVSS vector indicates it is remotely exploitable over the network with low attack complexity and no user interaction.
Which installations are affected?
Maps Marker Pro versions 4.32 and earlier are affected according to the provided information. The data does not identify a fixed version or provide a workaround for organizations that cannot patch immediately.
What is the likely impact of successful exploitation?
The supplied CVSS vector rates confidentiality impact as high and availability impact as low. It also indicates scope can change, while integrity impact is rated none.