plugin

Wp Google Street View Vulnerabilities

11 known security issues reported for the Wp Google Street View WordPress plugin. Most recent disclosed Jan 8, 2026.

4 medium

Running Wp Google Street View on your site? Check whether your installed version is affected.

Scan your site free

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpgsv_map' Shortcode

medium

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpgsv_map' shortcode in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated at...

CVSS:
6.4
Affected:
up to 1.1.8
Fixed in:
1.1.9
Disclosed:
Jan 8, 2026

CVE-2026-0563 on NVD →

WP Google Street View <= 1.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WP Google Street View plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts i...

CVSS:
4.4
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Mar 27, 2025

CVE-2025-30799 on NVD →

WP Google Street View (with 360° virtual tour) &amp; Google maps + Local SEO [wp-google-street-view] < 1.1.6

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pagup WP Google Street View allows Stored XSS. This issue affects WP Google Street View: from n/a through 1.1.5.

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Mar 27, 2025

CVE-2025-30799 on NVD →

WP Google Street View (with 360° virtual tour) &amp; Google maps + Local SEO [wp-google-street-view] < 1.1.4

unknown

[en] The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgsv' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Jan 24, 2025

CVE-2024-13542 on NVD →

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgsv' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

CVSS:
6.4
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Jan 23, 2025

CVE-2024-13542 on NVD →

WP Google Street View (with 360° virtual tour) &amp; Google maps + Local SEO [wp-google-street-view] < 1.0.9

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

WP Google Street View (with 360° virtual tour) &amp; Google maps + Local SEO [wp-google-street-view] < 1.0.9

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Mar 4, 2022

WP Google Street View (with 360° virtual tour) &amp; Google maps + Local SEO [wp-google-street-view] < 1.0.9

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin (versions <= 1.0.8).

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Feb 28, 2022

WP Google Street View (with 360° virtual tour) &amp; Google maps + Local SEO [wp-google-street-view] < 1.0.9

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin (versions <= 1.0.8).

Affected:
up to 1.0.9
Fixed in:
1.0.9
Disclosed:
Feb 28, 2022

WP Google Street View (with 360° virtual tour) &amp; Google maps + Local SEO [wp-google-street-view] < 1.1.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.1.1
Fixed in:
1.1.1

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database