All verified exploits

CVE-2026-2580 Unauthenticated SQL Injection via WP Maps Orderby Parameter

Deterministic high WordPress Added cve-verified-cve-2026-2580

Detects WordPress installs running the WP Maps plugin (wp-google-map-plugin) at version 4.9.1 or earlier. The prepare_items() method in class.tabular.php reads the orderby GET parameter through sanitize_text_field() and interpolates it directly into an SQL ORDER BY clause without whitelist validation. The unauthenticated AJAX handler (wpgmp_ajax_call) exposes internal methods to any visitor. An attacker can extract database contents including admin credentials and customer data. Update to WP Maps 4.9.2 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-2580?

Scan your domain free