WordPress · Wp Maps – Store Locator · CVE-2026-2580
**Name of the Vulnerable Software and Affected Versions**
WP Maps – Store Locator, Google Maps, OpenStreetMap, Mapbox, Listing, Directory & Filters plugin for WordPress versions up to and including 4.9.1
**Description**
The WP Maps plugin for WordPress is susceptible to time-based SQL Injection. This is due to inadequate escaping of user-supplied input and insufficient preparation of existing SQL queries, specifically through the `orderby` parameter. This allows unauthenticated attackers to inject additional SQL queries into existing database queries, potentially extracting sensitive information.
**Recommendations**
Update the WP Maps – Store Locator, Google Maps, OpenStreetMap, Mapbox, Listing, Directory & Filters plugin to a version later than 4.9.1.