The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
We have discovered 14,320 live websites that are affected by CVE-2026-2580.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 14,320 live websites (77% of WP Google Map Plugin install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 40 versions ( 95% of all versions) |
| 3,742 websites | |
| 1,550 websites | |
| 955 websites | |
| 820 websites | |
| 726 websites | |
| 479 websites | |
| 472 websites | |
| 426 websites | |
| 319 websites | |
| 282 websites |
| .com | 5,682 websites |
| .de | 912 websites |
| .it | 663 websites |
| .org | 630 websites |
| .co.uk | 421 websites |
| .nl | 402 websites |
| .pl | 349 websites |
| .fr | 325 websites |
| .net | 280 websites |
| .com.au | 266 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.com | **,*** | ||
| ***.be | **,*** | ||
| *************.com | ***,*** | ||
| **.**.id | ***,*** | ||
| *******.*****.fr | ***,*** | ||
| ***************.com | ***,*** | ||
| ****.es | ***,*** | ||
| *******************.com | ***,*** | ||
| ****************.se | ***,*** | ||
| ******************.com | ***,*** |
FAQ