Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66618 at the National Vulnerability Database