Wp Go Maps
by WordPress
CVEs (24)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-0593 | Med | 0.27 | 5.3 | 0.00 | Jan 24, 2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated… | ||
| CVE-2026-15381 | Low | 0.24 | 3.7 | 0.00 | Jul 31, 2026 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | ||
| CVE-2023-4839 | Med | 0.22 | 4.4 | 0.00 | Mar 13, 2024 | The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | ||
| CVE-2026-25466 | Med | 0.00 | 5.3 | 0.00 | Jul 23, 2026 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. |
- risk 0.27cvss 5.3epss 0.00
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated…
- risk 0.24cvss 3.7epss 0.00
The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
- risk 0.22cvss 4.4epss 0.00
The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…
- risk 0.00cvss 5.3epss 0.00
Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.
Page 2 of 2