HIGH

CVE-2026-18464

2026-08-09 CVSS v3.1
CVSS
7.5

Description

The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.

Weakness (CWE)

CWE-400 Uncontrolled Resource Consumption

EPSS Score

0.3%
Probability of exploitation in next 30 days
22.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE