WP Go Maps – Google Map, OpenStreetMap, Leaflet Map < 10.1.04 - Unauthenticated SQL Injection
high
The WP Go Maps – Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to SQL Injection in versions up to 10.1.04 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append a...
- CVSS:
- 7.5
- Affected:
- up to 10.1.04
- Fixed in:
- 10.1.04
- Disclosed:
- Aug 4, 2026
CVE-2026-15381 on NVD →
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map <= 10.1.05 - Missing Authorization
medium
The WP Go Maps – Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 10.1.05. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 10.1.05
- Fixed in:
- 10.1.06
- Disclosed:
- Jul 22, 2026
CVE-2026-25466 on NVD →
WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation
medium
The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary rec...
- CVSS:
- 5.3
- Affected:
- up to 10.1.01
- Fixed in:
- 10.1.02
- Disclosed:
- Jun 19, 2026
CVE-2026-12238 on NVD →
WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
medium
The WP Go Maps plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.0.09 via the datatables AJAX fallback route. This makes it possible for unauthenticated attackers to extract marker records that the site owner has not approved for public display, including the...
- CVSS:
- 5.3
- Affected:
- up to 10.0.09
- Fixed in:
- 10.0.10
- Disclosed:
- Jun 5, 2026
CVE-2026-8385 on NVD →
Go Maps <= 10.0.9 - Unauthenticated Information Exposure
medium
The Go Maps plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 10.0.9. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 10.0.9
- Fixed in:
- 10.0.10
- Disclosed:
- May 25, 2026
CVE-2026-8386 on NVD →
WP Go Maps - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings vulnerability
medium
Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings vulnerability
- CVSS:
- 6.5
- Affected:
- up to 10.0.05
- Fixed in:
- 10.0.06
- Disclosed:
- Mar 18, 2026
WP Go Maps (formerly WP Google Maps) <= 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings' h...
- CVSS:
- 6.4
- Affected:
- up to 10.0.05
- Fixed in:
- 10.0.06
- Disclosed:
- Mar 17, 2026
CVE-2026-4268 on NVD →
WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and...
- CVSS:
- 5.3
- Affected:
- up to 10.0.04
- Fixed in:
- 10.0.05
- Disclosed:
- Jan 24, 2026
CVE-2026-0593 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.48
unknown
[en] The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.
- Affected:
- up to 9.0.48
- Fixed in:
- 9.0.48
- Disclosed:
- Nov 11, 2025
CVE-2025-11307 on NVD →
Google Maps <= 9.0.47 - Unauthenticated Stored Cross-Site Scripting
high
The Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...
- CVSS:
- 7.2
- Affected:
- up to 9.0.47
- Fixed in:
- 9.0.48
- Disclosed:
- Oct 21, 2025
CVE-2025-11307 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.49
unknown
[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison...
- Affected:
- up to 9.0.49
- Fixed in:
- 9.0.49
- Disclosed:
- Oct 18, 2025
CVE-2025-11703 on NVD →
WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the...
- CVSS:
- 5.3
- Affected:
- up to 9.0.48
- Fixed in:
- 9.0.49
- Disclosed:
- Oct 17, 2025
CVE-2025-11703 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.47
unknown
[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic rea...
- Affected:
- up to 9.0.47
- Fixed in:
- 9.0.47
- Disclosed:
- Oct 9, 2025
CVE-2025-11166 on NVD →
WP Go Maps (formerly WP Google Maps) <= 9.0.46 - Cross-Site Request Forgery to Plugin Settings Update
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic reachabl...
- CVSS:
- 5.4
- Affected:
- up to 9.0.46
- Fixed in:
- 9.0.47
- Disclosed:
- Oct 8, 2025
CVE-2025-11166 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.41
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WP Go Maps (formerly WP Google Maps) WP Go Maps. This issue affects WP Go Maps: from n/a through 9.0.40.
- Affected:
- up to 9.0.41
- Fixed in:
- 9.0.41
- Disclosed:
- Jan 27, 2025
CVE-2025-24742 on NVD →
WP Go Maps <= 9.0.40 - Cross-Site Request Forgery
medium
The WP Go Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.40. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick...
- CVSS:
- 4.3
- Affected:
- up to 9.0.40
- Fixed in:
- 9.0.41
- Disclosed:
- Jan 24, 2025
CVE-2025-24742 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.39
unknown
[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level perm...
- Affected:
- up to 9.0.39
- Fixed in:
- 9.0.39
- Disclosed:
- Jun 14, 2024
CVE-2024-5994 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.39
unknown
<p>WordPress WP Google Maps Plugin <= 9.0.38 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: WP Google Maps</p><p>Link: https://wordpress.org/plugins/wp-google-maps/#developers</p><p>Affected Version <= 9.0.38</p><p>Fixed in version 9.0.39 </p>
- Affected:
- up to 9.0.39
- Fixed in:
- 9.0.39
- Disclosed:
- Jun 14, 2024
WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level permissio...
- CVSS:
- 6.4
- Affected:
- up to 9.0.38
- Fixed in:
- 9.0.39
- Disclosed:
- Jun 13, 2024
CVE-2024-5994 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.37
unknown
[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated...
- Affected:
- up to 9.0.37
- Fixed in:
- 9.0.37
- Disclosed:
- May 24, 2024
CVE-2024-3557 on NVD →
WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac...
- CVSS:
- 6.4
- Affected:
- up to 9.0.36
- Fixed in:
- 9.0.37
- Disclosed:
- May 23, 2024
CVE-2024-3557 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.35
unknown
[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. Whi...
- Affected:
- up to 9.0.35
- Fixed in:
- 9.0.35
- Disclosed:
- Apr 9, 2024
CVE-2023-6777 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.30
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Go Maps (formerly WP Google Maps) WP Google Maps allows Reflected XSS.This issue affects WP Google Maps: from n/a through 9.0.29.
- Affected:
- up to 9.0.30
- Fixed in:
- 9.0.30
- Disclosed:
- Mar 27, 2024
CVE-2024-29931 on NVD →
WP Google Maps <= 9.0.29 - Reflected Cross-Site Scripting
medium
The WP Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.0.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...
- CVSS:
- 6.1
- Affected:
- up to 9.0.29
- Fixed in:
- 9.0.30
- Disclosed:
- Mar 25, 2024
CVE-2024-29931 on NVD →
WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While th...
- CVSS:
- 5.3
- Affected:
- up to 9.0.34
- Fixed in:
- 9.0.35
- Disclosed:
- Mar 18, 2024
CVE-2023-6777 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.33
unknown
[en] The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary w...
- Affected:
- up to 9.0.33
- Fixed in:
- 9.0.33
- Disclosed:
- Mar 13, 2024
CVE-2023-4839 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.33
unknown
[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...
- Affected:
- up to 9.0.33
- Fixed in:
- 9.0.33
- Disclosed:
- Mar 13, 2024
CVE-2024-1582 on NVD →
WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...
- CVSS:
- 6.4
- Affected:
- up to 9.0.32
- Fixed in:
- 9.0.33
- Disclosed:
- Mar 12, 2024
CVE-2024-1582 on NVD →
WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web sc...
- CVSS:
- 4.4
- Affected:
- up to 9.0.32
- Fixed in:
- 9.0.33
- Disclosed:
- Mar 12, 2024
CVE-2023-4839 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.29
unknown
[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary we...
- Affected:
- up to 9.0.29
- Fixed in:
- 9.0.29
- Disclosed:
- Jan 24, 2024
CVE-2023-6697 on NVD →
WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- CVSS:
- 6.1
- Affected:
- up to 9.0.28
- Fixed in:
- 9.0.29
- Disclosed:
- Jan 23, 2024
CVE-2023-6697 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.28
unknown
[en] The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.
- Affected:
- up to 9.0.28
- Fixed in:
- 9.0.28
- Disclosed:
- Jan 8, 2024
CVE-2023-6627 on NVD →
WP Google Maps <= 9.0.27 - Unauthenticated Stored Cross-Site Scripting via REST API
medium
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 9.0.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 9.0.27
- Fixed in:
- 9.0.28
- Disclosed:
- Dec 18, 2023
CVE-2023-6627 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 9.0.16
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions.
- Affected:
- up to 9.0.16
- Fixed in:
- 9.0.16
- Disclosed:
- Mar 14, 2023
CVE-2022-47595 on NVD →
WP Go Maps <= 9.0.15 - Authenticated (Admin+) Directory Traversal
medium
The WP Go Maps plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.0.15 via the 'wpgmza_xml_location' option accessed in 'getXMLCacheDirPath'. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive informatio...
- CVSS:
- 4.9
- Affected:
- up to 9.0.15
- Fixed in:
- 9.0.16
- Disclosed:
- Jan 20, 2023
CVE-2022-47595 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 8.1.13
unknown
[en] Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.
- Affected:
- up to 8.1.13
- Fixed in:
- 8.1.13
- Disclosed:
- Sep 9, 2021
CVE-2021-36870 on NVD →
WP Google Maps <= 8.1.12 - Authenticated Stored Cross-Site Scripting
medium
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.
- CVSS:
- 5.5
- Affected:
- up to 8.1.13
- Fixed in:
- 8.1.13
- Disclosed:
- Sep 8, 2021
CVE-2021-36870 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 8.1.12
unknown
[en] The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
- Affected:
- up to 8.1.12
- Fixed in:
- 8.1.12
- Disclosed:
- Jun 21, 2021
CVE-2021-24383 on NVD →
WP Google Maps <= 8.1.11 - Authenticated Stored Cross-Site Scripting
medium
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
- CVSS:
- 5.4
- Affected:
- up to 8.1.12
- Fixed in:
- 8.1.12
- Disclosed:
- Jun 7, 2021
CVE-2021-24383 on NVD →
WP Go Maps (formerly WP Google Maps) <= 7.11.17 - SQL Injection
critical
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
- CVSS:
- 9.8
- Affected:
- up to 7.11.17
- Fixed in:
- 7.11.18
- Disclosed:
- Sep 9, 2020
CVE-2019-10692 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.11.35
unknown
[en] The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
- Affected:
- up to 7.11.35
- Fixed in:
- 7.11.35
- Disclosed:
- Aug 9, 2019
CVE-2019-14792 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.11.35
unknown
Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WP Google Maps plugin (versions <= 7.11.34).
- Affected:
- up to 7.11.35
- Fixed in:
- 7.11.35
- Disclosed:
- Jul 10, 2019
WP Google Maps <= 7.11.34 - Cross-Site Request Forgery to Cross-Site Scripting
medium
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
- CVSS:
- 6.1
- Affected:
- up to 7.11.35
- Fixed in:
- 7.11.35
- Disclosed:
- Jul 8, 2019
CVE-2019-14792 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.11.28
unknown
Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WP Google Maps plugin (versions <= 7.11.27).
- Affected:
- up to 7.11.28
- Fixed in:
- 7.11.28
- Disclosed:
- Jun 16, 2019
WP Google Maps <= 7.11.27 - Cross-Site Request Forgery
medium
The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.27. This is due to missing nonce validation on the wpgmza_settings_page_post() function. This makes it possible for authenticated attackers to modify the plugin's settings.
- CVSS:
- 4.3
- Affected:
- up to 7.11.28
- Fixed in:
- 7.11.28
- Disclosed:
- Jun 3, 2019
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.11.28
unknown
The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.27. This is due to missing nonce validation on the wpgmza_settings_page_post() function. This makes it possible for authenticated attackers to modify the plugin's settings.
- Affected:
- up to 7.11.28
- Fixed in:
- 7.11.28
- Disclosed:
- Jun 3, 2019
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.11.18
unknown
[en] In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
- Affected:
- up to 7.11.18
- Fixed in:
- 7.11.18
- Disclosed:
- Apr 2, 2019
CVE-2019-10692 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.11.18
unknown
Unauthenticated SQL Injection (SQLi) vulnerability found by Thomas Chauchefoin in WordPress WP Google Maps plugin (versions <= 7.11.17).
- Affected:
- up to 7.11.18
- Fixed in:
- 7.11.18
- Disclosed:
- Apr 2, 2019
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.10.43
unknown
[en] The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
- Affected:
- up to 7.10.43
- Fixed in:
- 7.10.43
- Disclosed:
- Mar 21, 2019
CVE-2019-9912 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.10.43
unknown
Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Google Maps plugin (versions <= 7.10.41).
- Affected:
- up to 7.10.43
- Fixed in:
- 7.10.43
- Disclosed:
- Mar 12, 2019
WP Google Maps < 7.10.43 - Reflected Cross-Site Scripting
medium
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
- CVSS:
- 6.1
- Affected:
- up to 7.10.41
- Fixed in:
- 7.10.43
- Disclosed:
- Feb 5, 2019
CVE-2019-9912 on NVD →
WP Google Maps <= 6.3.14 - Stored Cross-Site Scripting
medium
The WP Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_store_locator_query_string’ parameter in versions up to, and including, 6.3.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 6.3.14
- Fixed in:
- 6.3.15
- Disclosed:
- Nov 10, 2016
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 6.3.15
unknown
The WP Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_store_locator_query_string’ parameter in versions up to, and including, 6.3.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scrip...
- Affected:
- up to 6.3.15
- Fixed in:
- 6.3.15
- Disclosed:
- Nov 10, 2016
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 2.1.4
unknown
Because of this vulnerability, the attackers can steal users' session tokens, or perform arbitrary actions on their behalf.
Update the plugin.
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Aug 15, 2016
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 3.0.0
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Aug 20, 2015
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 6.0.27
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.ph...
- Affected:
- up to 6.0.27
- Fixed in:
- 6.0.27
- Disclosed:
- Oct 22, 2014
CVE-2014-7182 on NVD →
WP Google Maps <= 6.0.26 - Reflected Cross-Site Scripting
medium
The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.26 via the 'poly_id' parameter (in the edit_poly, edit_polyline, or edit_marker actions) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.1
- Affected:
- up to 6.0.27
- Fixed in:
- 6.0.27
- Disclosed:
- Oct 15, 2014
CVE-2014-7182 on NVD →
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 7.11.28
unknown
The WP Google Maps WordPress plugin was affected by an Admin Settings CSRF security vulnerability.
- Affected:
- up to 7.11.28
- Fixed in:
- 7.11.28
WP Go Maps (formerly WP Google Maps) [wp-google-maps] < 6.3.15
unknown
The WP Google Maps WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) via CSRF security vulnerability.
- Affected:
- up to 6.3.15
- Fixed in:
- 6.3.15