CVE-2026-18464
7.5WP MAPS PRO · WP MAPS PRO
The WP MAPS PRO WordPress plugin is vulnerable to uncontrolled resource consumption due to a missing capability check in an AJAX action, allowing unauthenticated attackers to cause a denial of service.
Executive summary
A critical vulnerability in the WP MAPS PRO WordPress plugin allows unauthenticated attackers to exhaust server resources and trigger a denial of service.
Vulnerability
This is an uncontrolled resource consumption vulnerability caused by a lack of capability checks in an AJAX action. The flaw allows unauthenticated attackers to trigger uncontrolled recursion that exhausts server memory and CPU.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation results in a denial of service, which can lead to significant system downtime and operational disruption. While the flaw does not expose sensitive data, the impact on availability can hinder business continuity for organizations relying on the affected website.
Remediation
Immediate Action: Update the WP MAPS PRO plugin to version 6.1.3 or later to apply the necessary capability checks.
Proactive Monitoring: Monitor server resource utilization, specifically CPU and memory usage, for sudden spikes that may indicate exploitation attempts.
Compensating Controls: Implement a Web Application Firewall (WAF) to filter malicious AJAX requests and limit access to the vulnerable plugin endpoints.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The vulnerability poses a clear risk to service availability. Administrators should prioritize updating the WP MAPS PRO plugin immediately to version 6.1.3 to remediate the flaw and prevent potential denial of service attacks.