Junglewise Threat Intelligence

CVE-2026-66618: WP Maps SQL injection

CVE-2026-66618 · Severity: high · CVSS 7.6 · Published 2026-09-17

Technologies: WP Maps. Vendors: WP Maps.

Executive brief

WP Maps is a popular WordPress plugin for embedding maps on websites. A SQL injection vulnerability in versions 4.9.9 and earlier allows authenticated administrators to read, modify, or delete the entire database, including user credentials and sensitive data stored in WordPress. This could lead to complete site compromise and data loss.

Technical details

The WP Maps plugin versions 4.9.9 and earlier contain a SQL injection vulnerability that requires administrator-level privileges to exploit. The vulnerability stems from insufficient input sanitization in a database query operation. An authenticated administrator can craft malicious SQL statements to access, modify, or delete database records. While the attack requires authentication at the admin level, successful exploitation enables full database disclosure and manipulation, including extraction of user passwords and sensitive information. The vulnerability has been patched in version 5.0.0.

Affected products

  • WP Maps WP Maps <=4.9.9

Timeline

  • 2026-09-17: disclosed: Published by Patchstack
  • 2026-09-17: patched: Patched in version 5.0.0

References

Related threats