Impact
The Maps Marker Pro plugin for WordPress contains an unauthenticated SQL injection flaw in all releases up to 4.32. Unsanitized data fed into the backend allows an attacker to send arbitrary SQL through the plugin’s public endpoints. This can give the attacker read or write access to the WordPress database, enabling full site defacement, credential theft, or data destruction. The flaw is a classic CWE‑89 SQL injection.
Affected Systems
Any WordPress site that has the Maps Marker Pro plugin installed in a version 4.32 or earlier. The issue affects all platforms where WordPress and the plugin run; there is no restriction to specific OS or server software.
Risk and Exploitability
The flaw has a CVSS score of 9.3, placing it in the critical category. An EPSS score of 0.00236 (<1%) indicates a low probability of exploitation, though the high severity suggests significant risk. The vulnerability is exploitable without authentication, meaning any external user who can reach the plugin’s input URLs can trigger the injection. Because it is not included in the CISA KEV list, there is no evidence of large‑scale active exploitation yet, but the potential for damage warrants urgent mitigation.
OpenCVE Enrichment