CM Map Locations <= 2.1.8 - Authenticated (Subscriber+) Arbitrary File Upload via cmloc_route_image_upload AJAX Action
high
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all versions up to, and including, 2.1.8 via the uploadMedia function. This is due to insufficient file type validation in the upload handler, which performs incomplete extens...
- CVSS:
- 8.8
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.9
- Disclosed:
- Aug 24, 2026
CVE-2026-16601 on NVD →
CM Map Locations <= 2.1.6 - Reflected Cross-Site Scripting
medium
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.7
- Disclosed:
- Jul 21, 2025
CVE-2025-48151 on NVD →
CM Map Locations <= 2.0.8 - Reflected Cross-Site Scripting
medium
The CM Map Locations plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Feb 11, 2025
CVE-2025-24758 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database