Sploitus

CVE-2026-39492

2 known exploits for CVE-2026-39492

Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

Affected products
Wp Amaps, Wp-Google-Map-Plugin
CVSS 3.1
9.3 CRITICAL
EPSS
0.4% (29th percentile)
Weakness
CWE-89
NVD status
Deferred
Published
2026-06-15
Attack patterns
CAPEC-7
Entry point
location_id request body
Path
wp-admin/admin-ajax.php

Fix

Update the WordPress WP Maps Plugin to the latest available version (at least 4.9.2).

CVE-2026-39492 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-39492

Proof-of-concept code and exploit modules indexed by Sploitus