What is CVE-2026-16265?
This vulnerability exists in the WP Maps WordPress plugin before version 4.9.7. A missing capability check in an AJAX action allows Subscriber-level users to trigger uncontrolled recursion, exhausting server resources and causing a Denial of Service (DoS). Updating to the latest version is recommended.
Azərbaycanca: Bu boşluq WP Maps WordPress plaginində 4.9.7 versiyasından əvvəlki versiyalarda mövcuddur. AJAX əməliyyatında icazə yoxlaması olmadığı üçün Subscriber roluna malik istifadəçi idarəolunmaz rekursiya yarada bilər ki, bu da server resurslarını tükədərək Denial of Service (DoS) hücumuna səbəb olur. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which plugin and via which user role can CVE-2026-16265 be exploited?
This vulnerability exists in the WP Maps WordPress plugin before version 4.9.7 and can be exploited by a user with the Subscriber role.
What type of attack results from successful exploitation of CVE-2026-16265?
Successful exploitation triggers uncontrolled recursion, exhausting server resources and causing a Denial of Service (DoS) attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.