Description
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
Published: 2026-09-17
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection leading to unauthorized database access
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows an attacker to inject arbitrary SQL statements through the WordPress WP Maps plugin’s administrator interface. The injection flaw permits reading, modifying, or deleting database contents, potentially exposing sensitive data or corrupting site content. The weakness lies in improper validation of user input before database execution, as identified by CWE-89.

Affected Systems

The flaw affects installations of the Flipper Code WP Maps WordPress plugin with versions 4.9.9 and earlier. Users running any update prior to 5.0.0 are vulnerable. The vulnerability is specific to the WP Maps plugin and does not extend to other WordPress components.

Risk and Exploitability

The CVSS score of 7.6 indicates a high severity with an impact that can be mitigated by patching. The EPSS score is not available, so real‑world exploitation probability is unknown; however, the flaw is publicly documented and the KEV status is not listed, implying no known active exploits at this time. Attackers who can reach the admin interface or possess administrative credentials can potentially exploit the injection point to compromise the database. If an attacker gains control of the database, they could exfiltrate data or inject malicious content, affecting confidentiality, integrity, and availability of the site.

Generated by OpenCVE AI on September 17, 2026 at 21:46 UTC.

Remediation

Vendor Solution

Update the WordPress WP Maps Plugin to the latest available version (at least 5.0.0).


OpenCVE Recommended Actions

  • Update the WordPress WP Maps Plugin to version 5.0.0 or later, which removes the injection vector.
  • If the plugin cannot be updated immediately, temporarily disable the WP Maps plugin or remove its admin pages to prevent exploitation via the admin interface.
  • Limit access to the WordPress admin area to trusted IP addresses or enforce two‑factor authentication to reduce the chance that an attacker can reach the vulnerable interface.

Generated by OpenCVE AI on September 17, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Flippercode
Flippercode wp Maps
Wordpress-extensions
Wordpress-extensions wp Maps
Vendors & Products Flippercode
Flippercode wp Maps
Wordpress-extensions
Wordpress-extensions wp Maps

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Administrator SQL Injection in WP Maps <= 4.9.9 versions.
Title WordPress WP Maps plugin <= 4.9.9 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Flippercode Wp Maps
Wordpress-extensions Wp Maps
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-17T14:05:51.372Z

Reserved: 2026-07-27T14:00:21.730Z

Link: CVE-2026-66618

cve-icon Vulnrichment

Updated: 2026-09-17T14:05:23.251Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:17.753

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-66618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T13:22:38Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')