Detects WordPress installs running the WP Maps plugin (wp-google-map-plugin) at version 4.9.1 or earlier. The prepare_items() method in class.tabular.php reads the orderby GET parameter through sanitize_text_field() and interpolates it directly into an SQL ORDER BY clause without whitelist validation. The unauthenticated AJAX handler (wpgmp_ajax_call) exposes internal methods to any visitor. An attacker can extract database contents including admin credentials and customer data. Update to WP Maps 4.9.2 or later.
Is your app exploitable through CVE-2026-2580?
Scan your domain free