CVE-2026-2580: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2580 is a time-based SQL Injection vulnerability in the WP Maps – Store Locator, Google Maps, OpenStreetMap, Mapbox, Listing, Directory & Filters plugin for WordPress. It affects all versions up to and including 4.9.1, and was disclosed on March 23, 2026, with Wordfence credited as the assigner. The flaw carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and stems from insufficient escaping of the user-supplied orderby parameter combined with a lack of prepared statements in the plugin's SQL query construction (Wordfence). The vulnerable code paths are located in core/class.tabular.php (line 780), classes/wpgmp-helper.php (line 127), and wp-google-map-plugin.php (line 77) (WordPress Trac). An unauthenticated attacker can append malicious SQL clauses to existing queries via the orderby parameter, exploiting the time-based blind injection technique to infer database contents through response timing differences. No authentication or special privileges are required, and no user interaction is needed.

Impact

Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials (hashed passwords), email addresses, API keys, and other confidential site data. The CVSS score reflects a high confidentiality impact with no integrity or availability impact, meaning the attack is read-only but can expose data sufficient for account takeover or further attacks (Wordfence, Red Hat CVE). Extracted credentials could enable lateral movement into the WordPress admin panel or connected systems.

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed as of the time of reporting. The EPSS score is approximately 0.071%, indicating a low but non-negligible probability of exploitation in the near term (Feedly). The vulnerability has been detected by Qualys scanners (detection ID 531158) and is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The unauthenticated nature of the flaw lowers the exploitation barrier significantly, making it attractive to automated scanning tools.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Maps plugin (versions ≤ 4.9.1) using tools like WPScan, Shodan, or Google dorks (e.g., inurl:wp-google-map-plugin).
  2. Locate vulnerable endpoint: Identify the plugin's front-end map listing or directory page that accepts an orderby GET/POST parameter.
  3. Craft time-based payload: Inject a time-based SQL payload into the orderby parameter, such as orderby=IF(1=1,SLEEP(5),0), to confirm the injection point by observing a delayed server response.
  4. Enumerate database: Use automated tools like sqlmap with the --technique=T (time-based blind) flag to systematically extract database names, table names, and column contents: sqlmap -u "https://target.com/map-page/?orderby=1" --technique=T --dbs.
  5. Extract sensitive data: Target the wp_users table to retrieve usernames and hashed passwords, then attempt offline cracking or credential stuffing against the WordPress admin login (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual HTTP requests to map/listing pages containing SQL keywords (SLEEP, IF, BENCHMARK, UNION, SELECT) in the orderby parameter; repeated requests with incrementally varying payloads from a single IP.
  • Logs: WordPress access logs showing requests like GET /map-page/?orderby=IF(1%3D1%2CSLEEP(5)%2C0) or similar encoded SQL fragments; abnormally high response times (≥5 seconds) for specific map-related endpoints.
  • Web Application Firewall (WAF) Alerts: Triggered rules for SQL injection patterns on parameters associated with the WP Maps plugin endpoints.
  • Database: Unexpected or high-frequency slow queries logged in MySQL slow query log originating from WordPress database user, particularly involving SLEEP() or conditional time-delay functions.

Mitigation and workarounds

Users should update the WP Maps plugin to a version above 4.9.1 as soon as a patched release is made available by the vendor (flippercode). In the interim, site administrators should consider disabling the plugin entirely if map/directory functionality is not critical, or restrict access to affected pages via IP allowlisting. Deploying a Web Application Firewall (WAF) with SQL injection rules (e.g., Wordfence, Cloudflare WAF) can provide partial mitigation by blocking malicious orderby payloads (Wordfence, Sucuri Blog).

Community reactions

Wordfence included CVE-2026-2580 in its weekly WordPress vulnerability report for the period of March 16–22, 2026, highlighting it among notable disclosures (Wordfence Blog). Sucuri also referenced the vulnerability in its March 2026 vulnerability patch roundup (Sucuri Blog). Social media activity was observed on Mastodon and Bluesky shortly after disclosure, primarily from automated security feed accounts, with no significant researcher commentary or controversy noted.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management