VYPR

Wp Google Map Plugin

by WordPress

Source repositories

CVEs (13)

  • CVE-2026-39492CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

  • CVE-2015-9309HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.

  • CVE-2015-9308HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.

  • CVE-2015-9307HigAug 14, 2019
    risk 0.57cvss 8.8epss 0.01

    The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.

  • CVE-2024-2386HigJun 29, 2024
    risk 0.50cvss 8.8epss 0.00

    The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2021-24130HigMar 18, 2021
    risk 0.47cvss 7.2epss 0.01

    Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).

  • CVE-2025-11365MedOct 15, 2025
    risk 0.42cvss 6.5epss 0.00

    The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2016-10878MedAug 12, 2019
    risk 0.40cvss 6.1epss 0.01

    The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.

  • CVE-2015-9305MedAug 12, 2019
    risk 0.40cvss 6.1epss 0.01

    The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.

  • CVE-2023-23878MedApr 4, 2023
    risk 0.38cvss 5.9epss 0.00

    Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.

  • CVE-2022-25600MedMar 11, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).

  • CVE-2018-0577MedMay 14, 2018
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-9594MedJun 6, 2026
    risk 0.29cvss 4.4epss 0.00

    The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization…