
CVE-2026-18464 The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and do… https://www.cve.org/CVERecord?id=CVE-2026-18464
Post summary
WP MAPS PRO WordPress plugin versions before 6.1.3 are vulnerable due to a missing capability check on an AJAX endpoint, allowing unauthenticated users to potentially exploit the flaw.

