THREAT OPS › Threat News › [NVD] CVE-2026-18464 — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion
[NVD] CVE-2026-18464 — The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion
CVE-2026-18464 CVSS: None Published: 2026-08-09T06:18:34.450
The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not restrict the operation it dispatches, allowing unauthenticated attackers to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of
Indicators of compromise
- CVE-2026-18464cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18464