WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service
Summary
| CVE | CVE-2026-18464 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-09 06:18:34 UTC |
| Updated | 2026-08-09 06:18:34 UTC |
| Description | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service. |
Risk And Classification
EPSS: 0.001450000 probability, percentile 0.042810000 (date 2026-08-09)
Problem Types: CWE-400 Uncontrolled Resource Consumption
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | WP MAPS PRO | affected 6.1.3 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/45d1c2c2-c5da-43b6-a982-5323fb8d9014 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Mohammad Aghdasi (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.