PT-2026-24581 · Flippercode · Wp Maps – Store Locator

Johska

·

Published

2026-03-11

·

Updated

2026-03-15

·

CVE-2026-3222

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Maps versions up to and including 4.9.1
Description The WP Maps plugin for WordPress is susceptible to time-based blind SQL Injection through the location id parameter. This occurs because the plugin’s database abstraction layer (FlipperCode Model Base::is column()) interprets user input enclosed in backticks as column names, circumventing the esc sql() escaping function. The wpgmp ajax call AJAX handler, accessible to unauthenticated users via wp ajax nopriv, permits the invocation of arbitrary class methods, including wpgmp return final capability. This function directly incorporates the unsanitized location id GET parameter into database queries, enabling attackers to append additional SQL queries and potentially extract sensitive data.
Recommendations Versions up to and including 4.9.1 should be updated to a newer, fixed version if available. As a temporary workaround, consider restricting access to the wpgmp ajax call AJAX handler. Avoid using the location id parameter in the affected API endpoint until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-3222

Affected Products

Wp Maps – Store Locator