WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings
wp-google-map-plugin · plugin
Known security vulnerabilities for WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings. Find out in seconds which version runs on your site with WP Lens.
20 known vulnerabilities
1 critical · 10 exploitable without logging in · 1 with public exploit code · latest Sep 25, 2026
Listed on wordpress.org · latest 5.0.1 · last updated Sep 24, 2026 · 60K+ installs
wordpress.org status checked on Oct 6, 2026
Vulnerabilities
- Critical 9.3
CVE-2026-39492unauthenticated≤ 4.9.1
WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability
- High 8.8
CVE-2023-28172unauthenticated · needs a click≤ 4.4.2
WordPress WP Google Map Plugin Plugin <= 4.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
- High 8.8
CVE-2022-25600unauthenticated · needs a click≤ 4.2.3
WordPress WP Google Map plugin <= 4.2.3 - Cross-Site Request Forgery (CSRF) vulnerability
- High 8.8
CVE-2015-9309unauthenticated · needs a click
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
- High 8.8
CVE-2015-9308unauthenticated · needs a click
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
- High 8.8
CVE-2015-9307unauthenticated · needs a click
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
- High 8.8
CVE-2024-2386contributor+≤ 4.6.1
WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection
- High 7.6
CVE-2026-66618admin≤ 4.9.9
WordPress WP Maps plugin <= 4.9.9 - SQL Injection vulnerability
- High 7.5
CVE-2026-2580unauthenticated≤ 4.9.1
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter
- High 7.5
CVE-2026-3222unauthenticated≤ 4.9.1
WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter
- High 7.5
CVE-2026-13456subscriber+≤ 4.9.8
WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter
- Medium 6.6
CVE-2025-67535high privilege≤ 4.8.6
WordPress WP Maps plugin <= 4.8.6 - PHP Object Injection vulnerability
- Medium 6.4
CVE-2026-13179subscriber+≤ 4.9.8
WP Maps <= 4.9.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter
- Medium 6.4
CVE-2025-13364contributor+≤ 4.8.7
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pu
- Medium 6.1
CVE-2016-10878unauthenticated · needs a click
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
- Medium 6.1
CVE-2015-9305unauthenticated · needs a click
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
- Medium 5.4
CVE-2018-0577login required
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary
- Medium 5.4
CVE-2023-23878editor+≤ 4.3.9
WordPress WP Google Map Plugin Plugin <= 4.3.9 is vulnerable to Cross Site Scripting (XSS)
- Medium 4.4
CVE-2026-9594admin≤ 4.9.4
WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
- Medium 4.3
CVE-2026-28144login required≤ 4.9.6
WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).