CVE Database /
CVE-2026-16265
CVE
CVE-2026-16265 — WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-16265
|
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.7 |
Uncontrolled Resource Consumption |
Unknown
|
< 4.9.7
|
4.9.7 |
2026-08-07 |
—
|
CVE-2026-16265
The WP Maps plugin for WordPress, prior to version 4.9.7, contains an oversight in its handling of AJAX requests. Specifically, the plugin fails to verify user permissions before executing certain actions, enabling users with minimal privileges to initiate recursive processes that can deplete server resources and cause a system failure.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings