WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
wp-google-maps · plugin
Known security vulnerabilities for WP Go Maps – Google Map, OpenStreetMap, Leaflet Map. Find out in seconds which version runs on your site with WP Lens.
20 known vulnerabilities
1 critical · 10 exploitable without logging in · 3 with public exploit code · latest Sep 2, 2026
Listed on wordpress.org · latest 10.1.10 · last updated Sep 28, 2026 · 300K+ installs
wordpress.org status checked on Oct 2, 2026
Vulnerabilities
- Critical 9.8
CVE-2019-10692unauthenticated
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before
- High 8.8
CVE-2025-24742unauthenticated · needs a click≤ 9.0.40
WordPress WP Google Maps plugin <= 9.0.40 - Cross Site Request Forgery (CSRF) vulnerability
- Medium 6.5
CVE-2023-6777unauthenticated≤ 9.0.34
WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service
- Medium 6.5
CVE-2022-47595high privilege≤ 9.0.15
WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversal
- Medium 6.4
CVE-2026-4268subscriber+≤ 10.0.05
WP Go Maps (formerly WP Google Maps) <= 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_se
- Medium 6.1
CVE-2024-29931unauthenticated · needs a click≤ 9.0.29
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
- Medium 6.1
CVE-2023-6697unauthenticated · needs a click≤ 9.0.28
WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting
- Medium 5.4
CVE-2025-11166unauthenticated · needs a click≤ 9.0.46
WP Go Maps (formerly WP Google Maps) <= 9.0.46 - Cross-Site Request Forgery to Plugin Settings Update
- Medium 5.4
CVE-2019-14792login required
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
- Medium 5.4
CVE-2024-5994contributor+≤ 9.0.38
WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting
- Medium 5.4
CVE-2024-3557contributor+≤ 9.0.36
WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 5.4
CVE-2024-1582contributor+≤ 9.0.32
WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
- Medium 5.4
CVE-2021-36870high privilege≤ 8.1.12
WordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent XSS vulnerabilities
- Medium 5.3
CVE-2026-84780unauthenticated≤ 10.1.08
WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability
- Medium 5.3
CVE-2026-25466unauthenticated≤ 10.1.04
WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability
- Medium 5.3
CVE-2026-12238unauthenticated≤ 10.1.01
WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation
- Medium 5.3
CVE-2025-11703unauthenticated≤ 9.0.48
WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning
- Medium 5.3
CVE-2026-0593subscriber+≤ 10.0.04
WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification
- Medium 4.8
CVE-2023-4839admin≤ 9.0.32
WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scripting
- Medium 4.3
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to injec
The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).