Junglewise Threat Intelligence

CVE-2026-84780: WP Go Maps denial of service in map rendering

CVE-2026-84780 · Severity: medium · CVSS 5.3 · Published 2026-09-02

Technologies: WP Go Maps. Vendors: WP Go Maps.

Executive brief

WP Go Maps is a popular WordPress plugin that displays interactive maps on websites. An unauthenticated attacker can send specially crafted requests to the plugin, overwhelming the server and causing the website to become slow or go offline. This vulnerability requires no special privileges and can be exploited by anyone over the network.

Technical details

This vulnerability is a denial of service (DoS) attack in WP Go Maps versions 10.1.08 and earlier, classified as an insecure design flaw. The plugin fails to properly validate or rate-limit unauthenticated requests to a critical component, allowing an attacker to send a flood of malicious requests that consume server resources. No authentication is required to exploit this vulnerability. The attack can render the website unavailable to legitimate users. The vendor has patched this issue in version 10.1.09; affected users should update immediately.

Affected products

  • WP Go Maps WP Go Maps <= 10.1.08

Timeline

  • 2026-09-02: disclosed: Published by Patchstack
  • 2026-09-02: patched: Patched in version 10.1.09

References

Related threats