CVE-2026-18466: CWE-284 Improper Access Control in WP Maps
CVE-2026-18466 is an improper access control vulnerability in the WP Maps WordPress plugin before version 4.9.8. The plugin fails to perform capability checks and nonce validation in one of its AJAX actions. This flaw allows users with Subscriber-level accounts to create unlimited database options, which are loaded on every page request, potentially impacting site performance.
AI Analysis
Technical Summary
The WP Maps WordPress plugin versions prior to 4.9.8 do not enforce proper access control or nonce validation on a specific AJAX action. As a result, authenticated users with minimal privileges (Subscriber role) can abuse this flaw to create an unlimited number of options entries in the database. These options are loaded on every page request, which can degrade site performance or availability. The vulnerability is classified under CWE-284 (Improper Access Control).
Potential Impact
An attacker with a Subscriber account can exploit this vulnerability to create a large number of database options entries, which are loaded on every page request. This can lead to degraded performance or denial of service conditions due to resource exhaustion. There is no direct confidentiality impact, but integrity and availability impacts are present.
Mitigation Recommendations
A fixed version of WP Maps is available starting from version 4.9.8. Users should upgrade to version 4.9.8 or later to remediate this vulnerability. Since this is not a cloud service, remediation requires updating the plugin. No additional mitigations are indicated by the vendor advisory.
CVE-2026-18466: CWE-284 Improper Access Control in WP Maps
Description
CVE-2026-18466 is an improper access control vulnerability in the WP Maps WordPress plugin before version 4.9.8. The plugin fails to perform capability checks and nonce validation in one of its AJAX actions. This flaw allows users with Subscriber-level accounts to create unlimited database options, which are loaded on every page request, potentially impacting site performance.
CVSS v3.1
Score 5.4medium
Affected software
WP Maps
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WP Maps WordPress plugin versions prior to 4.9.8 do not enforce proper access control or nonce validation on a specific AJAX action. As a result, authenticated users with minimal privileges (Subscriber role) can abuse this flaw to create an unlimited number of options entries in the database. These options are loaded on every page request, which can degrade site performance or availability. The vulnerability is classified under CWE-284 (Improper Access Control).
Potential Impact
An attacker with a Subscriber account can exploit this vulnerability to create a large number of database options entries, which are loaded on every page request. This can lead to degraded performance or denial of service conditions due to resource exhaustion. There is no direct confidentiality impact, but integrity and availability impacts are present.
Mitigation Recommendations
A fixed version of WP Maps is available starting from version 4.9.8. Users should upgrade to version 4.9.8 or later to remediate this vulnerability. Since this is not a cloud service, remediation requires updating the plugin. No additional mitigations are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-31T08:01:35.190Z
- State
- PUBLISHED
Threat ID: 6a854e93c6e8be033248b291
Added to database: 08/19/2026, 06:34:59 UTC
Last enriched: 09/11/2026, 09:48:43 UTC
Last updated: 10/02/2026, 07:19:30 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.