
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18464 is an unauthenticated Denial of Service vulnerability in the WP MAPS PRO WordPress plugin (also known as wp-google-map-gold) affecting all versions before 6.1.3. The flaw allows unauthenticated remote attackers to exhaust server resources by triggering uncontrolled recursion through an unsecured AJAX action. It was publicly disclosed on August 3, 2026, and assigned by WPScan; the original researcher is Mohammad Aghdasi (WPScan). The CVSS category is estimated as Medium, with an EPSS score of 0.0 (GitHub Advisory).
The root cause is a missing capability check (CWE-400: Uncontrolled Resource Consumption) in one of the plugin's AJAX action handlers, which is registered and accessible to unauthenticated users. Because the action does not restrict the operations it dispatches, an attacker can craft a request that causes the server-side code to enter uncontrolled recursion, consuming PHP execution stack and server memory until resources are exhausted. No authentication or special privileges are required — the vulnerable endpoint is reachable by any network user (WPScan, GitHub Advisory). A proof-of-concept is scheduled for public release on September 11, 2026, to allow time for users to update (WPScan).
Successful exploitation causes a Denial of Service by exhausting server resources (CPU, memory, or PHP process stack), which can crash or render the affected WordPress site unavailable to legitimate users. Because the attack requires no authentication, any internet-facing WordPress installation running a vulnerable version of WP MAPS PRO is at risk. There is no evidence of confidentiality or integrity impact; the primary consequence is availability loss (WPScan, GitHub Advisory).
There is currently no public proof-of-concept exploit available; WPScan has withheld PoC details until September 11, 2026. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (WPScan, GitHub Advisory).
/wp-content/plugins/wp-google-map-gold/).POST /wp-admin/admin-ajax.php with an action parameter corresponding to the vulnerable handler.admin-ajax.php with the specific action value that triggers the uncontrolled recursion, without supplying any authentication credentials or nonce./wp-admin/admin-ajax.php from a single or small set of IP addresses, particularly with a specific action parameter value associated with the WP MAPS PRO plugin.admin-ajax.php; PHP error logs showing fatal errors such as Maximum function nesting level reached or Allowed memory size exhausted originating from WP MAPS PRO plugin files.The vendor (flippercode) has released version 6.1.3 of the WP MAPS PRO plugin, which addresses this vulnerability by implementing proper capability checks on the affected AJAX action. WordPress site administrators should update the plugin to version 6.1.3 or later immediately. If immediate patching is not possible, consider temporarily deactivating the plugin or restricting access to wp-admin/admin-ajax.php via firewall or WAF rules until the update can be applied (WPScan, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."