Skip to content
Noroxi

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

wp-google-maps · plugin

Known security vulnerabilities for WP Go Maps – Google Map, OpenStreetMap, Leaflet Map. Find out in seconds which version runs on your site with WP Lens.

20 known vulnerabilities

1 critical · 10 exploitable without logging in · 3 with public exploit code · latest Sep 2, 2026

Listed on wordpress.org · latest 10.1.10 · last updated Sep 28, 2026 · 300K+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2019-10692unauthenticated

    In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before

    Critical 9.8
  • CVE-2025-24742unauthenticated · needs a click≤ 9.0.40

    WordPress WP Google Maps plugin <= 9.0.40 - Cross Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2023-6777unauthenticated≤ 9.0.34

    WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service

    Medium 6.5
  • CVE-2022-47595high privilege≤ 9.0.15

    WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversal

    Medium 6.5
  • CVE-2026-4268subscriber+≤ 10.0.05

    WP Go Maps (formerly WP Google Maps) <= 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_se

    Medium 6.4
  • CVE-2024-29931unauthenticated · needs a click≤ 9.0.29

    WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability

    Medium 6.1
  • CVE-2023-6697unauthenticated · needs a click≤ 9.0.28

    WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting

    Medium 6.1
  • CVE-2025-11166unauthenticated · needs a click≤ 9.0.46

    WP Go Maps (formerly WP Google Maps) <= 9.0.46 - Cross-Site Request Forgery to Plugin Settings Update

    Medium 5.4
  • CVE-2019-14792login required

    The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.

    Medium 5.4
  • CVE-2024-5994contributor+≤ 9.0.38

    WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting

    Medium 5.4
  • CVE-2024-3557contributor+≤ 9.0.36

    WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2024-1582contributor+≤ 9.0.32

    WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

    Medium 5.4
  • CVE-2021-36870high privilege≤ 8.1.12

    WordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent XSS vulnerabilities

    Medium 5.4
  • CVE-2026-84780unauthenticated≤ 10.1.08

    WordPress WP Go Maps plugin <= 10.1.08 - Denial of Service Attack vulnerability

    Medium 5.3
  • CVE-2026-25466unauthenticated≤ 10.1.04

    WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability

    Medium 5.3
  • CVE-2026-12238unauthenticated≤ 10.1.01

    WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation

    Medium 5.3
  • CVE-2025-11703unauthenticated≤ 9.0.48

    WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning

    Medium 5.3
  • CVE-2026-0593subscriber+≤ 10.0.04

    WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification

    Medium 5.3
  • CVE-2023-4839admin≤ 9.0.32

    WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scripting

    Medium 4.8
  • CVE-2014-7182

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to injec

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory