HIGH
CVE-2026-18464
CVSS
7.5
Description
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
Weakness (CWE)
CWE-400
Uncontrolled Resource Consumption
EPSS Score
0.3%
Probability of exploitation in next 30 days
22.9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.