AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16265

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Maps plugin for WordPress versions prior to 4.9.7 is vulnerable due to a lack of capability checks in its AJAX actions, allowing users with Subscriber accounts to initiate uncontrolled recursion. This can lead to resource exhaustion on the server, resulting in a Denial of Service. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of service disruption.

CVE
CVE-2026-16265
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%
WordPress

Original NVD Description

The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.