What is CVE-2026-15381?
CVE-2026-15381 is a vulnerability in the WP Go Maps WordPress plugin before version 10.1.04. It arises from improper sanitization and escaping of a parameter before using it in a SQL query, leading to SQL injection attacks by unauthenticated users. Affected users should update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-15381, WP Go Maps WordPress plaginində 10.1.04 versiyasından əvvəl mövcud olan zəiflikdir. Plagin, SQL sorğusunda istifadə etməzdən əvvəl parametri düzgün təmizləmədiyi üçün autentifikasiya olunmamış istifadəçilər SQL inyeksiya hücumları həyata keçirə bilər. Bu zəiflikdən qorunmaq üçün plagin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the WP Go Maps plugin are vulnerable to CVE-2026-15381?
The vulnerability affects all versions of the plugin before version 10.1.04.
Is authentication required to exploit CVE-2026-15381?
No, this vulnerability allows unauthenticated users to carry out SQL injection attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.