What is CVE-2026-18464?
The WP MAPS PRO WordPress plugin before version 6.1.3 lacks a capability check in one of its AJAX actions, which is available to unauthenticated users. This vulnerability allows attackers to trigger uncontrolled recursion, exhausting server resources. Updating the plugin to the latest version is strongly recommended.
Azərbaycanca: WP MAPS PRO WordPress plaginində 6.1.3 versiyasından əvvəl bir AJAX əməliyyatında icazə yoxlanışı yoxdur. Bu zəiflik autentifikasiya olunmamış istifadəçilərə nəzarətsiz rekursiya tetikleməyə imkan verərək server resurslarını tükədir. Plaginin ən son versiyasına yenilənmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of the WP MAPS PRO plugin are affected by CVE-2026-18464?
All versions prior to 6.1.3 are affected by this vulnerability.
How does the CVE-2026-18464 vulnerability affect the server?
Unauthenticated attackers can trigger uncontrolled recursion, exhausting server resources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.