PT-2026-78294 · WordPress · Wp Amaps
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
WP Maps versions prior to 4.9.8
Description
An issue exists in an AJAX action where the software fails to perform a capability check and does not validate a nonce (a unique token used to prevent replay attacks). This allows users with a Subscriber account to create an unlimited number of options in the database, which are then loaded on every page request.
Recommendations
Update WP Maps to version 4.9.8 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Amaps