
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2580 is a time-based SQL Injection vulnerability in the WP Maps – Store Locator, Google Maps, OpenStreetMap, Mapbox, Listing, Directory & Filters plugin for WordPress. It affects all versions up to and including 4.9.1, and was disclosed on March 23, 2026, with Wordfence credited as the assigner. The flaw carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and stems from insufficient escaping of the user-supplied orderby parameter combined with a lack of prepared statements in the plugin's SQL query construction (Wordfence). The vulnerable code paths are located in core/class.tabular.php (line 780), classes/wpgmp-helper.php (line 127), and wp-google-map-plugin.php (line 77) (WordPress Trac). An unauthenticated attacker can append malicious SQL clauses to existing queries via the orderby parameter, exploiting the time-based blind injection technique to infer database contents through response timing differences. No authentication or special privileges are required, and no user interaction is needed.
Successful exploitation allows unauthenticated remote attackers to extract sensitive information from the WordPress database, including user credentials (hashed passwords), email addresses, API keys, and other confidential site data. The CVSS score reflects a high confidentiality impact with no integrity or availability impact, meaning the attack is read-only but can expose data sufficient for account takeover or further attacks (Wordfence, Red Hat CVE). Extracted credentials could enable lateral movement into the WordPress admin panel or connected systems.
No public exploit code or active in-the-wild exploitation has been confirmed as of the time of reporting. The EPSS score is approximately 0.071%, indicating a low but non-negligible probability of exploitation in the near term (Feedly). The vulnerability has been detected by Qualys scanners (detection ID 531158) and is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The unauthenticated nature of the flaw lowers the exploitation barrier significantly, making it attractive to automated scanning tools.
inurl:wp-google-map-plugin).orderby GET/POST parameter.orderby parameter, such as orderby=IF(1=1,SLEEP(5),0), to confirm the injection point by observing a delayed server response.sqlmap with the --technique=T (time-based blind) flag to systematically extract database names, table names, and column contents: sqlmap -u "https://target.com/map-page/?orderby=1" --technique=T --dbs.wp_users table to retrieve usernames and hashed passwords, then attempt offline cracking or credential stuffing against the WordPress admin login (Wordfence, WordPress Trac).SLEEP, IF, BENCHMARK, UNION, SELECT) in the orderby parameter; repeated requests with incrementally varying payloads from a single IP.GET /map-page/?orderby=IF(1%3D1%2CSLEEP(5)%2C0) or similar encoded SQL fragments; abnormally high response times (≥5 seconds) for specific map-related endpoints.SLEEP() or conditional time-delay functions.Users should update the WP Maps plugin to a version above 4.9.1 as soon as a patched release is made available by the vendor (flippercode). In the interim, site administrators should consider disabling the plugin entirely if map/directory functionality is not critical, or restrict access to affected pages via IP allowlisting. Deploying a Web Application Firewall (WAF) with SQL injection rules (e.g., Wordfence, Cloudflare WAF) can provide partial mitigation by blocking malicious orderby payloads (Wordfence, Sucuri Blog).
Wordfence included CVE-2026-2580 in its weekly WordPress vulnerability report for the period of March 16–22, 2026, highlighting it among notable disclosures (Wordfence Blog). Sucuri also referenced the vulnerability in its March 2026 vulnerability patch roundup (Sucuri Blog). Social media activity was observed on Mastodon and Bluesky shortly after disclosure, primarily from automated security feed accounts, with no significant researcher commentary or controversy noted.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."