Wp Google Map Plugin
by WordPress
Source repositories
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-39492 | Cri | 0.60 | 9.3 | 0.00 | Jun 15, 2026 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. | ||
| CVE-2015-9309 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. | ||
| CVE-2015-9308 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. | ||
| CVE-2015-9307 | Hig | 0.57 | 8.8 | 0.01 | Aug 14, 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. | ||
| CVE-2024-2386 | Hig | 0.50 | 8.8 | 0.00 | Jun 29, 2024 | The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient… | ||
| CVE-2021-24130 | Hig | 0.47 | 7.2 | 0.01 | Mar 18, 2021 | Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+). | ||
| CVE-2025-11365 | Med | 0.42 | 6.5 | 0.00 | Oct 15, 2025 | The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | ||
| CVE-2016-10878 | Med | 0.40 | 6.1 | 0.01 | Aug 12, 2019 | The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. | ||
| CVE-2015-9305 | Med | 0.40 | 6.1 | 0.01 | Aug 12, 2019 | The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions. | ||
| CVE-2023-23878 | Med | 0.38 | 5.9 | 0.00 | Apr 4, 2023 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions. | ||
| CVE-2022-25600 | Med | 0.35 | 5.4 | 0.01 | Mar 11, 2022 | Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3). | ||
| CVE-2018-0577 | Med | 0.35 | 5.4 | 0.01 | May 14, 2018 | Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2026-9594 | Med | 0.29 | 4.4 | 0.00 | Jun 6, 2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization… |
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
- risk 0.57cvss 8.8epss 0.01
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
- risk 0.57cvss 8.8epss 0.01
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
- risk 0.57cvss 8.8epss 0.01
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
- risk 0.50cvss 8.8epss 0.00
The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…
- risk 0.47cvss 7.2epss 0.01
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
- risk 0.42cvss 6.5epss 0.00
The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google_map' shortcode in all versions up to, and including, 1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
- risk 0.40cvss 6.1epss 0.01
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
- risk 0.40cvss 6.1epss 0.01
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
- risk 0.38cvss 5.9epss 0.00
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
- risk 0.35cvss 5.4epss 0.01
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.29cvss 4.4epss 0.00
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization…