Maps Plugin using Google Maps for WordPress – WP Google Map [gmap-embed] < 1.9.4
unknown
[en] The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setu...
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Feb 15, 2025
CVE-2024-13208 on NVD →
Maps Plugin using Google Maps for WordPress – WP Google Map [gmap-embed] < 1.9.4
unknown
[en] The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setu...
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Feb 15, 2025
CVE-2024-13306 on NVD →
Maps Plugin using Google Maps for WordPress – WP Google Map <= 1.9.3 - Maps Plugin using Google Maps for WordPress – WP Google Map <= 1.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Markers
medium
The Maps Plugin using Google Maps for WordPress – WP Google Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 1.9.3
- Fixed in:
- 1.9.4
- Disclosed:
- Jan 24, 2025
CVE-2024-13208 on NVD →
Maps Plugin using Google Maps for WordPress – WP Google Map <= 1.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Maps Plugin using Google Maps for WordPress – WP Google Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...
- CVSS:
- 4.4
- Affected:
- up to 1.9.3
- Fixed in:
- 1.9.4
- Disclosed:
- Jan 24, 2025
CVE-2024-13306 on NVD →
Maps Plugin using Google Maps for WordPress – WP Google Map [gmap-embed] < 1.8.1
unknown
[en] The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Feb 28, 2022
CVE-2021-25011 on NVD →
Maps Plugin using Google Maps for WordPress – WP Google Map [gmap-embed] < 1.8.4
unknown
[en] The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.4
- Disclosed:
- Feb 28, 2022
CVE-2021-25081 on NVD →
WP Google Map <= 1.8.3 - Arbitrary Post Deletion and Plugin Settings Update via Cross-Site Request Forgery
medium
The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack
- CVSS:
- 6.5
- Affected:
- up to 1.8.3
- Fixed in:
- 1.8.4
- Disclosed:
- Jan 27, 2022
CVE-2021-25081 on NVD →
Maps Plugin using Google Maps for WordPress – WP Google Map [gmap-embed] < 1.8.1
unknown
[en] The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Jan 25, 2022
CVE-2021-45729 on NVD →
WP Google Map <= 1.8.0 - Missing Authorization
medium
The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.
- CVSS:
- 5.4
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Dec 8, 2021
CVE-2021-45729 on NVD →
WP Google Map <= 1.8.0 - Subscriber+ Arbitrary Post Deletion and Plugin Settings Update
medium
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.
- CVSS:
- 5.7
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Dec 8, 2021
CVE-2021-25011 on NVD →
Maps Plugin using Google Maps for WordPress – WP Google Map [gmap-embed] < 1.7.7
unknown
[en] The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Aug 9, 2021
CVE-2021-24502 on NVD →
WP Google Map <= 1.7.6 - Admin+ Stored Cross-Site Scripting
medium
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
- CVSS:
- 4.8
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Jul 1, 2021
CVE-2021-24502 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database