The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger uncontrolled recursion that exhausts server resources, resulting in a Denial of Service.
CVE-2026-16265
NONE
EPSS 0.14%
Updated Aug 07, 2026
WordPress
CVE Details
CVE ID
CVE-2026-16265
Published Date
Aug 07, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.7th percentile (higher than 3.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory