CVE-2026-2580 is a high-severity time-based SQL Injection vulnerability (CVSS 7.5) affecting the WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress, specifically versions up to and including 4.9.1. This flaw stems from insufficient input sanitization on the 'orderby' parameter, enabling unauthenticated attackers to append malicious SQL queries and extract sensitive information from the database. The attack vector is network-based with low complexity, requiring no user interaction or privileges. Currently, there is no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB, though it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Flippercode | WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters | >= 0, <= 4.9.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.