Summary
CVE-2026-39492 is a critical unauthenticated SQL injection vulnerability in the WP Maps WordPress plugin (developed by Flipper Code, also distributed as wp-google-map-plugin), affecting all versions up to and including 4.9.1. With a CVSS v3.1 score of 9.3 (Critical), the flaw allows any unauthenticated remote attacker to inject malicious SQL statements via the location_id parameter and extract sensitive contents from the underlying WordPress database — including user credentials and personally identifiable information — with no authentication or user interaction required.
Technical details
- Root cause: The plugin’s database abstraction layer (
FlipperCode_Model_Base::is_column()) incorrectly treats user-supplied input wrapped in backtick characters as trusted SQL column identifiers. This logic flaw causes the function to bypass the plugin’s use of WordPress’sesc_sql()escaping mechanism, leaving the input unsanitized before it is incorporated into database queries. - Trigger conditions: An attacker sends a crafted HTTP request to WordPress’s
admin-ajax.phpendpoint with the action parameter set towpgmp_ajax_call. This handler is registered for unauthenticated users via WordPress’swp_ajax_noprivhook, making it reachable without any login session. - Attack vector: Fully remote and unauthenticated. No privileges and no user interaction are required. Exploitation requires only network access to the target WordPress site.
- Impact: Time-based blind SQL injection, enabling complete exfiltration of the WordPress database. The CVSS Scope metric is rated Changed (S:C), indicating that successful exploitation can impact resources beyond the vulnerable component itself. Confidentiality impact is rated High (C:H).
Affected software
- WP Maps (plugin slug:
wp-google-map-plugin) by Flipper Code — all versions ≤ 4.9.1
Severity
- CVSS v3.1 Base Score: 9.3 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Mitigation and recommended actions
- Immediate: Update the WP Maps plugin to version 4.9.2 or later via the WordPress plugin dashboard. Version 4.9.2 contains the vendor-provided fix for this vulnerability.
- If immediate patching is not feasible:
- Implement a WAF rule to block unauthenticated requests to
admin-ajax.phpcontainingaction=wpgmp_ajax_call. - Temporarily deactivate the WP Maps plugin until patching can be performed.
- Restrict external HTTP access to the
wp-admin/admin-ajax.phpendpoint where operationally possible.
- Implement a WAF rule to block unauthenticated requests to
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

