CVE-2026-39492 is an unauthenticated SQL injection vulnerability in WP Maps affecting version 4.9.1 and earlier. The available information indicates that attacker-controlled input is incorporated into backend database queries without sufficient sanitization or parameterization, allowing arbitrary SQL manipulation. No specific vulnerable parameter, endpoint, or function is provided in the supplied content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a standalone Python exploit/scanner for CVE-2026-39492, targeting the WordPress WP Maps plugin (wp-google-map-plugin) <= 4.9.1. The repo is small and focused: a single main script (cve_2026_39492.py), a README with usage and exploitation notes, and a minimal requirements.txt listing requests and urllib3. The exploit’s main capability is unauthenticated time-based blind SQL injection testing against the WordPress AJAX endpoint /wp-admin/admin-ajax.php using action=wpgmp_ajax_call and a malicious location_id parameter. The script first fingerprints the target by requesting plugin files under /wp-content/plugins/wp-google-map-plugin/, especially readme.txt, and attempts to parse the plugin version from the Stable tag. If the plugin is detected and appears vulnerable (or version is unknown), it sends a backtick-wrapped SQL payload based on SLEEP() to confirm injection through response timing. The code is more than a simple detector: it supports single-target and mass scanning, concurrent execution with ThreadPoolExecutor, optional output file writing, randomized User-Agent selection, HTTP/HTTPS probing, and optional credential extraction. The extraction mode uses blind SQLi to retrieve values from the wp_users table, specifically the admin username and password hash for ID=1. Based on the README and visible code, the intended workflow is detection -> confirmation -> extraction of credentials, which could then enable further compromise outside the script. Repository structure and purpose: - cve_2026_39492.py: primary exploit/scanner entry point; contains detection logic, vulnerability checks, timing-based SQLi probing, result handling, CLI parsing, and extraction routines. - README.md: documents the vulnerability, affected versions, attack flow, CLI usage, manual curl-based exploitation examples, and expected impact. - requirements.txt: dependencies for HTTP requests. - .gitignore: excludes caches and output artifacts. Overall, this is an operational exploit scanner for a web/network attack vector, not merely a detection template. It is designed to identify vulnerable WordPress sites at scale and optionally exfiltrate administrator credential material via blind SQL injection.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.