plugin

Wp Google Map Plugin Vulnerabilities

50 known security issues reported for the Wp Google Map Plugin WordPress plugin. Most recent disclosed Aug 21, 2026.

1 critical 12 high 16 medium

Running Wp Google Map Plugin on your site? Check whether your installed version is affected.

Scan your site free

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters < 4.9.8 - Missing Authorization

medium

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to unauthorized access in all versions up to 4.9.8. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
4.3
Affected:
up to 4.9.8
Fixed in:
4.9.8
Disclosed:
Aug 21, 2026

CVE-2026-18466 on NVD →

Maps <= 4.9.6 - Authenticated (Subscriber+) Denial of Service

medium

The Maps plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 4.9.6. This is due to missing capability check and lack of an allowlist on the user-controlled `operation` parameter passed to a dynamic method call in the `wpgmp_ajax_call` function. This makes it possible for authentica...

CVSS:
6.5
Affected:
up to 4.9.6
Fixed in:
4.9.7
Disclosed:
Aug 3, 2026

CVE-2026-16265 on NVD →

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters <= 4.9.6 - Authenticated (Subscriber+) Information Exposure

medium

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.9.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or...

CVSS:
4.3
Affected:
up to 4.9.6
Fixed in:
4.9.7
Disclosed:
Jul 31, 2026

CVE-2026-28144 on NVD →

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters < 4.9.3 - Authenticated (Subscriber+) Local File Inclusion

high

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in versions up to 4.9.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, a...

CVSS:
7.5
Affected:
up to 4.9.3
Fixed in:
4.9.3
Disclosed:
Jun 11, 2026

CVE-2026-6381 on NVD →

WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter

medium

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible...

CVSS:
4.4
Affected:
up to 4.9.4
Fixed in:
4.9.5
Disclosed:
Jun 5, 2026

CVE-2026-9594 on NVD →

WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode

medium

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and output escaping on user-supplied shortco...

CVSS:
6.4
Affected:
up to 4.8.7
Fixed in:
4.8.8
Disclosed:
Apr 15, 2026

CVE-2025-13364 on NVD →

WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection

high

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

CVSS:
7.5
Affected:
up to 4.9.1
Fixed in:
4.9.2
Disclosed:
Apr 8, 2026

CVE-2026-39492 on NVD →

WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter

high

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...

CVSS:
7.5
Affected:
up to 4.9.1
Fixed in:
4.9.2
Disclosed:
Mar 22, 2026

CVE-2026-2580 on NVD →

WP Maps - Unauthenticated SQL Injection via 'location_id' Parameter vulnerability

critical

Unauthenticated SQL Injection via 'location_id' Parameter vulnerability

CVSS:
9.3
Affected:
up to 4.9.1
Fixed in:
4.9.2
Disclosed:
Mar 11, 2026

WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter

high

The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped in backticks as column names, bypassing...

CVSS:
7.5
Affected:
up to 4.9.1
Fixed in:
4.9.2
Disclosed:
Mar 10, 2026

CVE-2026-3222 on NVD →

WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion

high

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and above, t...

CVSS:
8.8
Affected:
up to 4.8.6
Fixed in:
4.8.7
Disclosed:
Feb 16, 2026

CVE-2025-12062 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.8.7

unknown

[en] The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and abo...

Affected:
up to 4.8.7
Fixed in:
4.8.7
Disclosed:
Feb 16, 2026

CVE-2025-12062 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] <= 4.8.6 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in WePlugins - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6.

Affected:
up to 4.8.6
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-67535 on NVD →

Maps <= 4.8.6 - Authenticated (Administrator+) PHP Object Injection

medium

The Maps plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable softw...

CVSS:
6.6
Affected:
up to 4.8.6
Fixed in:
4.8.7
Disclosed:
Nov 2, 2025

CVE-2025-67535 on NVD →

WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
4.4
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Apr 10, 2025

CVE-2025-3502 on NVD →

WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
4.4
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Apr 10, 2025

CVE-2025-3503 on NVD →

WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

CVSS:
4.4
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Apr 10, 2025

CVE-2025-3504 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.6.2

unknown

[en] The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....

Affected:
up to 4.6.2
Fixed in:
4.6.2
Disclosed:
Jun 29, 2024

CVE-2024-2386 on NVD →

WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection

high

The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...

CVSS:
8.8
Affected:
up to 4.6.1
Fixed in:
4.6.2
Disclosed:
Jun 28, 2024

CVE-2024-2386 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.4.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Nov 12, 2023

CVE-2023-28172 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.4.0

unknown

[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.

Affected:
up to 4.4.0
Fixed in:
4.4.0
Disclosed:
Apr 4, 2023

CVE-2023-23878 on NVD →

WP Google Map Plugin <= 4.4.2 - Cross-Site Request Forgery via delete()

medium

The WP Google Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.2. This is due to missing or incorrect nonce validation on the delete() function of the WPGMP_Model_Group_Map, WPGMP_Model_Location, and WPGMP_Model_Map classes. This makes it possible for una...

CVSS:
5.4
Affected:
up to 4.4.2
Fixed in:
4.4.3
Disclosed:
Mar 13, 2023

CVE-2023-28172 on NVD →

WP MAPS <= 4.3.9 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The WP MAPS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor level and above permiss...

CVSS:
5.5
Affected:
up to 4.3.9
Fixed in:
4.4.0
Disclosed:
Jan 20, 2023

CVE-2023-23878 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.4.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).

Affected:
up to 4.4.3
Fixed in:
4.4.3
Disclosed:
Mar 11, 2022

CVE-2022-25600 on NVD →

WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.2.3 - Cross-Site Request Forgery

medium

Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).

CVSS:
5.4
Affected:
up to 4.2.4
Fixed in:
4.2.4
Disclosed:
Feb 22, 2022

CVE-2022-25600 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.1.5

unknown

[en] Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).

Affected:
up to 4.1.5
Fixed in:
4.1.5
Disclosed:
Mar 18, 2021

CVE-2021-24130 on NVD →

WP Google Map Plugin <= 4.1.4 - Authenticated SQL Injection via Orderby

high

Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).

CVSS:
7.2
Affected:
up to 4.1.4
Fixed in:
4.1.5
Disclosed:
Nov 25, 2020

CVE-2021-24130 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.1.4

unknown

Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien (SunCSR) in WordPress WP Google Map Plugin (version <= 4.1.3).

Affected:
up to 4.1.4
Fixed in:
4.1.4
Disclosed:
Nov 25, 2020

WP Google Map Plugin <= 4.0.9 - Cross-Site Request Forgery to PHP Object Injection

high

The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to exploit PHP Object Injection via a forged request granted they...

CVSS:
8.8
Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Sep 21, 2019

WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.0.9 - Reflected Cross-Site Scripting

medium

The WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_ajax_fc_geocoding AJAX aciton in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping on user supplied input. This makes it po...

CVSS:
6.1
Affected:
up to 4.0.9
Fixed in:
4.1.0
Disclosed:
Sep 21, 2019

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.1.0

unknown

The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to exploit PHP Object Injection via a forged request granted they...

Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Sep 21, 2019

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.1.0

unknown

The WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_ajax_fc_geocoding AJAX aciton in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping on user supplied input. This makes it po...

Affected:
up to 4.1.0
Fixed in:
4.1.0
Disclosed:
Sep 21, 2019

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 2.3.10

unknown

[en] The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Aug 14, 2019

CVE-2015-9308 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 2.3.10

unknown

[en] The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.

Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Aug 14, 2019

CVE-2015-9309 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 2.3.10

unknown

[en] The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Aug 14, 2019

CVE-2015-9307 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 2.3.7

unknown

[en] The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.

Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Aug 12, 2019

CVE-2015-9305 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 3.1.2

unknown

[en] The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.

Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Aug 12, 2019

CVE-2016-10878 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.0.4

unknown

[en] Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
May 14, 2018

CVE-2018-0577 on NVD →

WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps < 4.0.4 - Cross-Site Scripting

medium

Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
5.4
Affected:
up to 4.0.4
Fixed in:
4.0.4
Disclosed:
Apr 27, 2018

CVE-2018-0577 on NVD →

WP Google Map Plugin <= 3.1.1 - Cross-Site Scripting

medium

The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.

CVSS:
6.1
Affected:
up to 3.1.2
Fixed in:
3.1.2
Disclosed:
Jul 27, 2016

CVE-2016-10878 on NVD →

WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery

high

The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

CVSS:
8.8
Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Aug 21, 2015

CVE-2015-9308 on NVD →

WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery

high

The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

CVSS:
8.8
Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Aug 21, 2015

CVE-2015-9307 on NVD →

WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery

high

The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.

CVSS:
8.8
Affected:
up to 2.3.10
Fixed in:
2.3.10
Disclosed:
Aug 21, 2015

CVE-2015-9309 on NVD →

WP Google Map Plugin < 3.0.0 - Cross-Site Request Forgery to Cross-Site Scripting

high

The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via several parameters in versions before 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

CVSS:
7.1
Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Aug 20, 2015

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 3.0.0

unknown

The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via several parameters in versions before 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Aug 20, 2015

WP Google Map Plugin < 2.3.7 - Reflected Cross-Site Scripting

medium

The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.

CVSS:
6.1
Affected:
up to 2.3.7
Fixed in:
2.3.7
Disclosed:
Apr 24, 2015

CVE-2015-9305 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.7.2

unknown
Affected:
up to 4.7.2
Fixed in:
4.7.2

CVE-2025-3502 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.7.2

unknown
Affected:
up to 4.7.2
Fixed in:
4.7.2

CVE-2025-3503 on NVD →

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 3.0.0

unknown

The lack of CSRF Protection could allow attackers to perform XSS attack against logged in administrators.

Affected:
up to 3.0.0
Fixed in:
3.0.0

WP Maps &#8211; Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory &amp; Filters [wp-google-map-plugin] < 4.1.0

unknown

The WP Google Map Plugin WordPress plugin was affected by a CSRF to Unauthenticated PHP Object Injection security vulnerability.

Affected:
up to 4.1.0
Fixed in:
4.1.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database