Skip to content
Noroxi

WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings

wp-google-map-plugin · plugin

Known security vulnerabilities for WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings. Find out in seconds which version runs on your site with WP Lens.

20 known vulnerabilities

1 critical · 10 exploitable without logging in · 1 with public exploit code · latest Sep 25, 2026

Listed on wordpress.org · latest 5.0.1 · last updated Sep 24, 2026 · 60K+ installs

wordpress.org status checked on Oct 6, 2026

Vulnerabilities

  • CVE-2026-39492unauthenticated≤ 4.9.1

    WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability

    Critical 9.3
  • CVE-2023-28172unauthenticated · needs a click≤ 4.4.2

    WordPress WP Google Map Plugin Plugin <= 4.4.2 is vulnerable to Cross Site Request Forgery (CSRF)

    High 8.8
  • CVE-2022-25600unauthenticated · needs a click≤ 4.2.3

    WordPress WP Google Map plugin <= 4.2.3 - Cross-Site Request Forgery (CSRF) vulnerability

    High 8.8
  • CVE-2015-9309unauthenticated · needs a click

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.

    High 8.8
  • CVE-2015-9308unauthenticated · needs a click

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

    High 8.8
  • CVE-2015-9307unauthenticated · needs a click

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

    High 8.8
  • CVE-2024-2386contributor+≤ 4.6.1

    WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection

    High 8.8
  • CVE-2026-66618admin≤ 4.9.9

    WordPress WP Maps plugin <= 4.9.9 - SQL Injection vulnerability

    High 7.6
  • CVE-2026-2580unauthenticated≤ 4.9.1

    WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter

    High 7.5
  • CVE-2026-3222unauthenticated≤ 4.9.1

    WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter

    High 7.5
  • CVE-2026-13456subscriber+≤ 4.9.8

    WP Maps <= 4.9.8 - Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter

    High 7.5
  • CVE-2025-67535high privilege≤ 4.8.6

    WordPress WP Maps plugin <= 4.8.6 - PHP Object Injection vulnerability

    Medium 6.6
  • CVE-2026-13179subscriber+≤ 4.9.8

    WP Maps <= 4.9.8 - Authenticated (Subscriber+) Stored Cross-Site Scripting via shapes_values Parameter

    Medium 6.4
  • CVE-2025-13364contributor+≤ 4.8.7

    WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pu

    Medium 6.4
  • CVE-2016-10878unauthenticated · needs a click

    The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.

    Medium 6.1
  • CVE-2015-9305unauthenticated · needs a click

    The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.

    Medium 6.1
  • CVE-2018-0577login required

    Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary

    Medium 5.4
  • CVE-2023-23878editor+≤ 4.3.9

    WordPress WP Google Map Plugin Plugin <= 4.3.9 is vulnerable to Cross Site Scripting (XSS)

    Medium 5.4
  • CVE-2026-9594admin≤ 4.9.4

    WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter

    Medium 4.4
  • CVE-2026-28144login required≤ 4.9.6

    WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory