What is CVE-2026-18466?
The WP Maps plugin before version 4.9.8 lacks a capability check and nonce validation in one of its AJAX actions, allowing users with a Subscriber role to create an unlimited number of database options that load on every page request. It is recommended to update the plugin to the latest version immediately.
Azərbaycanca: WP Maps plaqini 4.9.8 versiyasından əvvəl AJAX əməliyyatlarında səlahiyyət yoxlaması və nonce validasiyası aparmadığı üçün Abunəçi roluna malik istifadəçilər məlumat bazasında limitsiz sayda opsion yarada bilər ki, bu da hər səhifə yüklənməsində performans problemlərinə səbəb ola bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What vulnerability was discovered in older versions of the WP Maps plugin?
The plugin before version 4.9.8 lacks a capability check and nonce validation in its AJAX actions, allowing users with a Subscriber role to create an unlimited number of database options.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.