VYPR

Wp Go Maps

by WordPress

CVEs (24)

  • CVE-2026-0593MedJan 24, 2026
    risk 0.27cvss 5.3epss 0.00

    The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated…

  • CVE-2026-15381LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

  • CVE-2023-4839MedMar 13, 2024
    risk 0.22cvss 4.4epss 0.00

    The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level…

  • CVE-2026-25466MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

Page 2 of 2