PT-2026-78294 · WordPress · Wp Amaps

·

CVE-2026-18466

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions WP Maps versions prior to 4.9.8
Description An issue exists in an AJAX action where the software fails to perform a capability check and does not validate a nonce (a unique token used to prevent replay attacks). This allows users with a Subscriber account to create an unlimited number of options in the database, which are then loaded on every page request.
Recommendations Update WP Maps to version 4.9.8 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18466

Affected Products

Wp Amaps