Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

CVE-2026-18464: WP Maps Pro plugin < 6.1.3: Unauthenticated Denial of Service

CVE-2026-18464 · published 26 days ago
Summary

An attacker can crash the server running the WP Maps Pro plugin on a WordPress site, making it unavailable to users. This can happen if the plugin is not updated to the latest version, which fixes this issue. Update the plugin to version 6.1.3 or later to prevent this problem.

What to do
  • Update unknown wp maps pro to version 6.1.3 or later.
Affected software
VendorProductAffected versions
unknown wp maps pro < 6.1.3
Original advisory text
WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
References
Severity
7.5 High
Exploitation
EPSS <1%
Type
CWE-400Uncontrolled Resource Consumption
Timeline
Published9 Aug 2026
Updated30 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-18464 · MITRE
Monitor software like this
Free during beta