WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters < 4.9.8 - Missing Authorization
medium
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to unauthorized access in all versions up to 4.9.8. This is due to a missing capability check on a function. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 4.9.8
- Fixed in:
- 4.9.8
- Disclosed:
- Aug 21, 2026
CVE-2026-18466 on NVD →
Maps <= 4.9.6 - Authenticated (Subscriber+) Denial of Service
medium
The Maps plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 4.9.6. This is due to missing capability check and lack of an allowlist on the user-controlled `operation` parameter passed to a dynamic method call in the `wpgmp_ajax_call` function. This makes it possible for authentica...
- CVSS:
- 6.5
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.7
- Disclosed:
- Aug 3, 2026
CVE-2026-16265 on NVD →
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters <= 4.9.6 - Authenticated (Subscriber+) Information Exposure
medium
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.9.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or...
- CVSS:
- 4.3
- Affected:
- up to 4.9.6
- Fixed in:
- 4.9.7
- Disclosed:
- Jul 31, 2026
CVE-2026-28144 on NVD →
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters < 4.9.3 - Authenticated (Subscriber+) Local File Inclusion
high
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in versions up to 4.9.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary files on the server, a...
- CVSS:
- 7.5
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- Jun 11, 2026
CVE-2026-6381 on NVD →
WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
medium
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 4.4
- Affected:
- up to 4.9.4
- Fixed in:
- 4.9.5
- Disclosed:
- Jun 5, 2026
CVE-2026-9594 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode
medium
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and output escaping on user-supplied shortco...
- CVSS:
- 6.4
- Affected:
- up to 4.8.7
- Fixed in:
- 4.8.8
- Disclosed:
- Apr 15, 2026
CVE-2025-13364 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection
high
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...
- CVSS:
- 7.5
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.2
- Disclosed:
- Apr 8, 2026
CVE-2026-39492 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter
high
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation o...
- CVSS:
- 7.5
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.2
- Disclosed:
- Mar 22, 2026
CVE-2026-2580 on NVD →
WP Maps - Unauthenticated SQL Injection via 'location_id' Parameter vulnerability
critical
Unauthenticated SQL Injection via 'location_id' Parameter vulnerability
- CVSS:
- 9.3
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.2
- Disclosed:
- Mar 11, 2026
WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter
high
The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped in backticks as column names, bypassing...
- CVSS:
- 7.5
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.2
- Disclosed:
- Mar 10, 2026
CVE-2026-3222 on NVD →
WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion
high
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and above, t...
- CVSS:
- 8.8
- Affected:
- up to 4.8.6
- Fixed in:
- 4.8.7
- Disclosed:
- Feb 16, 2026
CVE-2025-12062 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7
unknown
[en] The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with Subscriber-level access and abo...
- Affected:
- up to 4.8.7
- Fixed in:
- 4.8.7
- Disclosed:
- Feb 16, 2026
CVE-2025-12062 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] <= 4.8.6 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in WePlugins - WordPress Development Company WP Maps wp-google-map-plugin allows Object Injection.This issue affects WP Maps: from n/a through <= 4.8.6.
- Affected:
- up to 4.8.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-67535 on NVD →
Maps <= 4.8.6 - Authenticated (Administrator+) PHP Object Injection
medium
The Maps plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable softw...
- CVSS:
- 6.6
- Affected:
- up to 4.8.6
- Fixed in:
- 4.8.7
- Disclosed:
- Nov 2, 2025
CVE-2025-67535 on NVD →
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...
- CVSS:
- 4.4
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Apr 10, 2025
CVE-2025-3502 on NVD →
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...
- CVSS:
- 4.4
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Apr 10, 2025
CVE-2025-3503 on NVD →
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...
- CVSS:
- 4.4
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Apr 10, 2025
CVE-2025-3504 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.6.2
unknown
[en] The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query....
- Affected:
- up to 4.6.2
- Fixed in:
- 4.6.2
- Disclosed:
- Jun 29, 2024
CVE-2024-2386 on NVD →
WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection
high
The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. Thi...
- CVSS:
- 8.8
- Affected:
- up to 4.6.1
- Fixed in:
- 4.6.2
- Disclosed:
- Jun 28, 2024
CVE-2024-2386 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- Nov 12, 2023
CVE-2023-28172 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.0
unknown
[en] Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
- Affected:
- up to 4.4.0
- Fixed in:
- 4.4.0
- Disclosed:
- Apr 4, 2023
CVE-2023-23878 on NVD →
WP Google Map Plugin <= 4.4.2 - Cross-Site Request Forgery via delete()
medium
The WP Google Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.2. This is due to missing or incorrect nonce validation on the delete() function of the WPGMP_Model_Group_Map, WPGMP_Model_Location, and WPGMP_Model_Map classes. This makes it possible for una...
- CVSS:
- 5.4
- Affected:
- up to 4.4.2
- Fixed in:
- 4.4.3
- Disclosed:
- Mar 13, 2023
CVE-2023-28172 on NVD →
WP MAPS <= 4.3.9 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The WP MAPS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with editor level and above permiss...
- CVSS:
- 5.5
- Affected:
- up to 4.3.9
- Fixed in:
- 4.4.0
- Disclosed:
- Jan 20, 2023
CVE-2023-23878 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
- Affected:
- up to 4.4.3
- Fixed in:
- 4.4.3
- Disclosed:
- Mar 11, 2022
CVE-2022-25600 on NVD →
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.2.3 - Cross-Site Request Forgery
medium
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
- CVSS:
- 5.4
- Affected:
- up to 4.2.4
- Fixed in:
- 4.2.4
- Disclosed:
- Feb 22, 2022
CVE-2022-25600 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.5
unknown
[en] Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
- Affected:
- up to 4.1.5
- Fixed in:
- 4.1.5
- Disclosed:
- Mar 18, 2021
CVE-2021-24130 on NVD →
WP Google Map Plugin <= 4.1.4 - Authenticated SQL Injection via Orderby
high
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
- CVSS:
- 7.2
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.5
- Disclosed:
- Nov 25, 2020
CVE-2021-24130 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.4
unknown
Authenticated SQL Injection (SQLi) vulnerability found by Nguyen Anh Tien (SunCSR) in WordPress WP Google Map Plugin (version <= 4.1.3).
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.4
- Disclosed:
- Nov 25, 2020
WP Google Map Plugin <= 4.0.9 - Cross-Site Request Forgery to PHP Object Injection
high
The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to exploit PHP Object Injection via a forged request granted they...
- CVSS:
- 8.8
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Sep 21, 2019
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.0.9 - Reflected Cross-Site Scripting
medium
The WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_ajax_fc_geocoding AJAX aciton in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping on user supplied input. This makes it po...
- CVSS:
- 6.1
- Affected:
- up to 4.0.9
- Fixed in:
- 4.1.0
- Disclosed:
- Sep 21, 2019
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.0
unknown
The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to exploit PHP Object Injection via a forged request granted they...
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Sep 21, 2019
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.0
unknown
The WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_ajax_fc_geocoding AJAX aciton in versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping on user supplied input. This makes it po...
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
- Disclosed:
- Sep 21, 2019
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.10
unknown
[en] The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.10
- Disclosed:
- Aug 14, 2019
CVE-2015-9308 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.10
unknown
[en] The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.10
- Disclosed:
- Aug 14, 2019
CVE-2015-9309 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.10
unknown
[en] The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.10
- Disclosed:
- Aug 14, 2019
CVE-2015-9307 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.7
unknown
[en] The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.7
- Disclosed:
- Aug 12, 2019
CVE-2015-9305 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 3.1.2
unknown
[en] The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Aug 12, 2019
CVE-2016-10878 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.0.4
unknown
[en] Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- May 14, 2018
CVE-2018-0577 on NVD →
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps < 4.0.4 - Cross-Site Scripting
medium
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 5.4
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- Apr 27, 2018
CVE-2018-0577 on NVD →
WP Google Map Plugin <= 3.1.1 - Cross-Site Scripting
medium
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jul 27, 2016
CVE-2016-10878 on NVD →
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
high
The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
- CVSS:
- 8.8
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.10
- Disclosed:
- Aug 21, 2015
CVE-2015-9308 on NVD →
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
high
The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
- CVSS:
- 8.8
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.10
- Disclosed:
- Aug 21, 2015
CVE-2015-9307 on NVD →
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
high
The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
- CVSS:
- 8.8
- Affected:
- up to 2.3.10
- Fixed in:
- 2.3.10
- Disclosed:
- Aug 21, 2015
CVE-2015-9309 on NVD →
WP Google Map Plugin < 3.0.0 - Cross-Site Request Forgery to Cross-Site Scripting
high
The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via several parameters in versions before 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- CVSS:
- 7.1
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Aug 20, 2015
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 3.0.0
unknown
The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via several parameters in versions before 3.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execut...
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Aug 20, 2015
WP Google Map Plugin < 2.3.7 - Reflected Cross-Site Scripting
medium
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
- CVSS:
- 6.1
- Affected:
- up to 2.3.7
- Fixed in:
- 2.3.7
- Disclosed:
- Apr 24, 2015
CVE-2015-9305 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.7.2
unknown
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.2
CVE-2025-3502 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.7.2
unknown
- Affected:
- up to 4.7.2
- Fixed in:
- 4.7.2
CVE-2025-3503 on NVD →
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 3.0.0
unknown
The lack of CSRF Protection could allow attackers to perform XSS attack against logged in administrators.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.0
unknown
The WP Google Map Plugin WordPress plugin was affected by a CSRF to Unauthenticated PHP Object Injection security vulnerability.
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0