CyberRota Analysis
AI-GeneratedThe WP Maps WordPress plugin prior to version 4.9.8 is vulnerable due to a lack of capability checks and nonce validation in its AJAX actions, enabling users with Subscriber accounts to create an unlimited number of database options. This can lead to excessive database bloat and potential performance degradation on affected sites. WordPress administrators, particularly those using the WP Maps plugin, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the database, each of which is loaded on every page request.