Description
Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
Published: 2026-09-02
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to trigger a denial of service in the WP Go Maps WordPress plugin when the version is 10.1.08 or earlier. By exploiting the unchecked input handling documented as CWE‑770, an attacker can cause the plugin to consume excessive system resources, rendering the affected WordPress site unusable. The impact is strictly on availability, as there is no direct path to data compromise or code execution. The CVSS score of 5.3 classifies the issue as moderate severity. The exploit requires only unauthenticated access to the plugin’s web interface.

Affected Systems

Any WordPress installation using the WP Go Maps plugin version 10.1.08 or earlier is affected. The vulnerability is specific to the WPGMaps:WP Go Maps plugin and does not extend to other WordPress components unless they integrate the same plugin logic. If the site has not applied the recommended update to version 10.1.09 or newer, it remains exposed.

Risk and Exploitability

With a CVSS of 5.3, the risk is moderate. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no currently known widespread exploitation. Based on the description, the attack vector is inferred to be a web‑based request that does not require authentication, allowing an attacker to create resource‑intensive operations. The vulnerability’s exploitability thus largely depends on the site’s exposure to the Internet and its ability to throttle or limit such requests.

Generated by OpenCVE AI on September 2, 2026 at 12:50 UTC.

Remediation

Vendor Solution

Update the WordPress WP Go Maps Plugin to the latest available version (at least 10.1.09).


OpenCVE Recommended Actions

  • Update the WP Go Maps WordPress plugin to at least version 10.1.09 to remove the resource exhaustion flaw.
  • If an upgrade cannot be performed immediately, disable the WP Go Maps plugin or block all traffic to its endpoints until the patch is applied to prevent denial of service attempts.
  • Implement rate limiting or server‑level resource caps on requests that target the WP Go Maps plugin to reduce the impact of any remaining unauthenticated input exploitation.

Generated by OpenCVE AI on September 2, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpgmaps
Wpgmaps wp Go Maps
Vendors & Products Wordpress
Wordpress wordpress
Wpgmaps
Wpgmaps wp Go Maps

Wed, 02 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.
Title WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Wordpress Wordpress
Wpgmaps Wp Go Maps
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-02T11:37:37.067Z

Reserved: 2026-09-02T09:57:48.859Z

Link: CVE-2026-84780

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-02T12:17:15.420

Modified: 2026-09-02T13:54:48.797

Link: CVE-2026-84780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T13:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling