plugin

Gmap Embed Vulnerabilities

12 known security issues reported for the Gmap Embed WordPress plugin. Most recent disclosed Feb 15, 2025.

6 medium

Running Gmap Embed on your site? Check whether your installed version is affected.

Scan your site free

Maps Plugin using Google Maps for WordPress &#8211; WP Google Map [gmap-embed] < 1.9.4

unknown

[en] The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setu...

Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Feb 15, 2025

CVE-2024-13208 on NVD →

Maps Plugin using Google Maps for WordPress &#8211; WP Google Map [gmap-embed] < 1.9.4

unknown

[en] The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setu...

Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Feb 15, 2025

CVE-2024-13306 on NVD →

Maps Plugin using Google Maps for WordPress – WP Google Map <= 1.9.3 - Maps Plugin using Google Maps for WordPress – WP Google Map <= 1.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting via Markers

medium

The Maps Plugin using Google Maps for WordPress – WP Google Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 1.9.3
Fixed in:
1.9.4
Disclosed:
Jan 24, 2025

CVE-2024-13208 on NVD →

Maps Plugin using Google Maps for WordPress – WP Google Map <= 1.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Maps Plugin using Google Maps for WordPress – WP Google Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 1.9.3
Fixed in:
1.9.4
Disclosed:
Jan 24, 2025

CVE-2024-13306 on NVD →

Maps Plugin using Google Maps for WordPress &#8211; WP Google Map [gmap-embed] < 1.8.1

unknown

[en] The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Feb 28, 2022

CVE-2021-25011 on NVD →

Maps Plugin using Google Maps for WordPress &#8211; WP Google Map [gmap-embed] < 1.8.4

unknown

[en] The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

Affected:
up to 1.8.4
Fixed in:
1.8.4
Disclosed:
Feb 28, 2022

CVE-2021-25081 on NVD →

WP Google Map <= 1.8.3 - Arbitrary Post Deletion and Plugin Settings Update via Cross-Site Request Forgery

medium

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

CVSS:
6.5
Affected:
up to 1.8.3
Fixed in:
1.8.4
Disclosed:
Jan 27, 2022

CVE-2021-25081 on NVD →

Maps Plugin using Google Maps for WordPress &#8211; WP Google Map [gmap-embed] < 1.8.1

unknown

[en] The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.

Affected:
up to 1.8.1
Fixed in:
1.8.1
Disclosed:
Jan 25, 2022

CVE-2021-45729 on NVD →

WP Google Map <= 1.8.0 - Missing Authorization

medium

The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authenticated low-role users to create, edit, and delete maps.

CVSS:
5.4
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
Dec 8, 2021

CVE-2021-45729 on NVD →

WP Google Map <= 1.8.0 - Subscriber+ Arbitrary Post Deletion and Plugin Settings Update

medium

The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated users, such as subscriber to delete arbitrary posts and update the plugin's settings.

CVSS:
5.7
Affected:
up to 1.8.0
Fixed in:
1.8.1
Disclosed:
Dec 8, 2021

CVE-2021-25011 on NVD →

Maps Plugin using Google Maps for WordPress &#8211; WP Google Map [gmap-embed] < 1.7.7

unknown

[en] The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Aug 9, 2021

CVE-2021-24502 on NVD →

WP Google Map <= 1.7.6 - Admin+ Stored Cross-Site Scripting

medium

The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed

CVSS:
4.8
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Jul 1, 2021

CVE-2021-24502 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database