{"error":0,"message":null,"data":{"name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map","plugin":"wp-google-maps","link":"https:\/\/wordpress.org\/plugins\/wp-google-maps\/","latest":"1790584200","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"962ea4f6c95862edca3e64684be2659ac7c6a43ddc0dbfd1219489bbb9cbadf0","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.1.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-36870","name":"CVE-2021-36870","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-36870","description":"[en] Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.","date":"2021-09-09"},{"id":"755fb396c7bbbd4fef9ce0c7a79dc38f21015211","name":"WordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-8-1-12-multiple-authenticated-persistent-cross-site-scripting-xss-vulnerabilities","description":"Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities discovered by Vlad Visse (Patchstack Red Team) in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.","date":"2021-06-15"},{"id":"4f3004f73d9a10f640b35719c0dc24fee1a04fbc","name":"WP Google Maps <= 8.1.12 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-8112-authenticated-stored-cross-site-scripting","description":"Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.","date":"2021-09-08"},{"id":"e85b24b6-4f5f-4dc9-801a-6699889b84c9","name":"WP Google Maps &lt; 8.1.13 - Multiple Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/e85b24b6-4f5f-4dc9-801a-6699889b84c9","description":"The plugin does not sanitise some of its fields, which could lead to Stored Cross-Site Scripting issues","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"5.5","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"5.5","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"60dfde17a0018fc25950d5a4fa32a02ac17b86cc826e14c4b25b5f9c4ec58fc2","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"8.1.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24383","name":"CVE-2021-24383","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24383","description":"[en] The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue","date":"2021-06-21"},{"id":"520da696929ededf528a4d3dcffa38e909049c08","name":"WordPress WP Google Maps plugin <= 8.1.11 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-8-1-11-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Mohammed Adam in WordPress WP Google Maps plugin (versions <= 8.1.11).","date":"2021-06-07"},{"id":"20a8237011ab5213dc958003f6d04f63dd573eb9","name":"WP Google Maps <= 8.1.11 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-8111-authenticated-stored-cross-site-scripting","description":"The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue","date":"2021-06-07"},{"id":"1270588c-53fe-447e-b83c-1b877dc7a954","name":"WP Google Maps &lt; 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/1270588c-53fe-447e-b83c-1b877dc7a954","description":"The plugin did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue\r\n\r\nNote: The vendor attributed the issue in the changelog to the wrong reporter (us, WPScan, as we reported it on behalf of the reporter). This will be corrected in the next version","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"2f1e658eeac7ccd350ca65a6306ed249f08b67331d3fad7da698a7d5151f35aa","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.35","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-14792","name":"CVE-2019-14792","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-14792","description":"[en] The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin\/ rectangle_name or rectangle_opacity parameter.","date":"2019-08-09"},{"id":"8f223ab8aee9c1a8a2baa2a87f440124e33b0bc0","name":"WP Google Maps <= 7.11.34 - Cross-Site Request Forgery to Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-71134-cross-site-request-forgery-to-cross-site-scripting","description":"The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin\/ rectangle_name or rectangle_opacity parameter.","date":"2019-07-08"},{"id":"7b392e1e-7c5b-4517-967f-cdffe126d292","name":"WP Google Maps &lt;= 7.11.34 - CSRF to Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/7b392e1e-7c5b-4517-967f-cdffe126d292","description":"Lack of CSRF and authorisation checks, as well as sanitisation in the wpgmaps_head() function in legacy-core.php can lead to stored XSS issues","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"f5b58a0cff10f02eb38016886058761c1721926ff9b9454356622ccd3fb6c5c1","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-10692","name":"CVE-2019-10692","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-10692","description":"[en] In the wp-google-maps plugin before 7.11.18 for WordPress, includes\/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.","date":"2019-04-02"},{"id":"14143dbbcc85af6210f859f41a36c54f62f445d2","name":"WP Go Maps (formerly WP Google Maps) <= 7.11.17 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-71117-sql-injection","description":"In the wp-google-maps plugin before 7.11.18 for WordPress, includes\/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.","date":"2020-09-09"},{"id":"475404ce-2a1a-4d15-bf02-df0ea2afdaea","name":"WP Google Maps 7.11.00-7.11.17 - Unauthenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/475404ce-2a1a-4d15-bf02-df0ea2afdaea","description":"The includes\/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement, leading to an unauthenticated SQL injection issue.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}]}},{"uuid":"ed3cd19fe3b53fe22fcac97dc499d377e5814fd34d0628edb52d44dc5e8d6b96","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.10.43","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.10.43","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-9912","name":"CVE-2019-9912","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-9912","description":"[en] The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin\/admin.php PATH_INFO.","date":"2019-03-21"},{"id":"a69c7b714b1b479e1ab15e32c597d4431a8d854b","name":"WordPress WP Google Maps plugin <= 7.10.41 - Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-7-10-41-cross-site-scripting-xss-vulnerability","description":"Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Google Maps plugin (versions <= 7.10.41).","date":"2019-03-22"},{"id":"8a8d79ed8ed2de943719b97ccef422c5728e3113","name":"WP Google Maps < 7.10.43 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-71043-reflected-cross-site-scripting","description":"The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin\/admin.php PATH_INFO.","date":"2019-02-05"},{"id":"d8a7ea0e-ca34-4b54-ab08-3f0a2c5b6d48","name":"WP Google Maps &lt;= 7.10.41 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/d8a7ea0e-ca34-4b54-ab08-3f0a2c5b6d48","description":"The WP Google Maps WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"63ff7e7fd71babd50acc34e90573f9d67081f627c05c374f2fd903381102900e","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.0.27","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.0.27","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2014-7182","name":"CVE-2014-7182","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2014-7182","description":"[en] Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin\/admin.php.","date":"2014-10-22"},{"id":"fcc16b9940cdf175404ccd80da118de298ee6444","name":"WordPress WP Google Maps Plugin <= 6.0.26 - Multiple XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-6-0-26-multiple-xss","description":"Because of these vulnerabilities, the  attackers can inject arbitrary web script or HTML via the \"poly_id\" parameter.\nUpdate the plugin.","date":"2014-09-25"},{"id":"25532a5b13cce8948b93b99657c9d10a3fb6a76a","name":"WP Google Maps <= 6.0.26 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-6026-reflected-cross-site-scripting","description":"The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.26 via the 'poly_id' parameter (in the edit_poly, edit_polyline, or edit_marker actions) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2014-10-15"},{"id":"62f6aef7-12e8-4542-ad2a-74dfb40d0686","name":"WP Google Maps 6.0.26 - Cross Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/62f6aef7-12e8-4542-ad2a-74dfb40d0686","description":"The WP Google Maps WordPress plugin was affected by a Cross Site Scripting (XSS) security vulnerability.","date":null}],"impact":{"cvss":{"version":null,"vector":null,"av":null,"ac":null,"pr":null,"ui":null,"s":null,"c":null,"i":null,"a":null,"score":"0.0","severity":null,"exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"770d68bc98ed9c3d43ce212f152b4406e171c5023504da85668b2cb1cd3a440e","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.35","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3e9e2761ce93ea3f48e6c14171435fc184eafa7e","name":"WordPress WP Google Maps plugin <= 7.11.34 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-7-11-34-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WP Google Maps plugin (versions <= 7.11.34).","date":"2019-07-10"}],"impact":[]},{"uuid":"4fee9d7b106aac8838a5dacd37488a9aa55722406d460932f8a402432efa22ce","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d6bd658fc531fb38b0f590ae2f039fd94f0cf420","name":"WordPress WP Google Maps plugin <= 7.11.27 - Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-7-11-27-cross-site-request-forgery-csrf-vulnerability","description":"Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WP Google Maps plugin (versions <= 7.11.27).","date":"2019-06-16"}],"impact":[]},{"uuid":"f69142f082139de47eb903e49c2eafa05df4252b12bad2ea9000c50a07a5e3e2","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.18","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.18","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"edc2c2023f82753871927d0614385b2bba5ce263","name":"WordPress WP Google Maps plugin <= 7.11.17 - Unauthenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-7-11-17-unauthenticated-sql-injection-sqli-vulnerability","description":"Unauthenticated SQL Injection (SQLi) vulnerability found by Thomas Chauchefoin in WordPress WP Google Maps plugin (versions <= 7.11.17).","date":"2019-04-02"}],"impact":[]},{"uuid":"51ff68969159c6d86150e216892f71e0dd7658abd029edb437c30431c899b5ad","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.10.43","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.10.43","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"7badf40d72f7034f8c868bd6f3b1e5ba1e259931","name":"WordPress WP Google Maps plugin <= 7.10.41 - Reflected Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-7-10-41-reflected-cross-site-scripting-xss-vulnerability","description":"Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Google Maps plugin (versions <= 7.10.41).","date":"2019-03-12"}],"impact":[]},{"uuid":"39af8226f5460f806817ae2d0919ae7ce0adbc7eed1eeead48821b52bb342711","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 2.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a73b45f4db3d415c79b963be8c3bc4df64beeae6","name":"WordPress Google Maps Plugin <= 2 2.1.3 - Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-google-maps-plugin-2-2-1-3-cross-site-scripting-xss","description":"Because of this vulnerability, the attackers can steal users' session tokens, or perform arbitrary actions on their behalf.\nUpdate the plugin.","date":"2016-08-15"}],"impact":[]},{"uuid":"8e16a7d4effffb8aab6419ec809535668a549db303ace4d6bd34d97c4ebd50da","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 3.0.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2e65f7330c24f7594da7d774d71aa4e2c478aba0","name":"WordPress Google Maps Plugin <= 2.3.9 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-google-maps-plugin-2-3-9-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary web script or HTML.\nUpdate the plugin.","date":"2015-08-20"}],"impact":[]},{"uuid":"923aae80c24dd7f24b4d717d8aea6ddf121c36e04e8dd8142a2eaa9de120fd54","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ccbde04e3e110794f90729cb1462fff3e84773aa","name":"WP Google Maps <= 7.11.27 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-71127-cross-site-request-forgery","description":"The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.27. This is due to missing nonce validation on the wpgmza_settings_page_post() function. This makes it possible for authenticated attackers to modify the plugin's settings.","date":"2019-06-03"}],"impact":[]},{"uuid":"74c36965e2507237ac2dc3632c0120e5cdf5ac78d1251045751195a55fbe848e","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8158860fed39ea47af86876908750bf9c0fd340e","name":"WP Google Maps <= 6.3.14 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-6314-stored-cross-site-scripting","description":"The WP Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018wpgmza_store_locator_query_string\u2019 parameter in versions up to, and including, 6.3.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2016-11-10"}],"impact":[]},{"uuid":"9653c65f3abfb9218e3affcb172c18c58640d21d382798a434f12b2d680de4be","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-47595","name":"CVE-2022-47595","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-47595","description":"[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <=\u00a09.0.15 versions.","date":"2023-03-14"},{"id":"31dd77623285aaee0de61338b6bfadcc81342c57","name":"WordPress  WP Google Maps Plugin  <= 9.0.15 is vulnerable to Directory Traversal","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-formerly-wp-google-maps-plugin-9-0-15-directory-traversal","description":"Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.16).\nrezaduty discovered and reported this Directory Traversal vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files\/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 9.0.16.","date":"2023-01-20"},{"id":"15b4daecd77bc786c816e3976f37484a7208c73a","name":"WP Go Maps <= 9.0.15 - Authenticated (Admin+) Directory Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-9015-authenticated-admin-directory-traversal","description":"The WP Go Maps plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.0.15 via the 'wpgmza_xml_location' option accessed in 'getXMLCacheDirPath'. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2023-01-20"},{"id":"7f4034e4-6b3a-48a3-84d6-f81b27868786","name":"WP Google Maps &lt; 9.0.16 - Admin+ Path Traversal","link":"https:\/\/wpscan.com\/vulnerability\/7f4034e4-6b3a-48a3-84d6-f81b27868786","description":"The plugin does not validate the XML Directory path settings, which could allow high privilege users such as admin to perform Path Traversal attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"4.9","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"4.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-22","name":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","description":"The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"d95bba1fe45420d3aa415cd009375787d465cc9b429040cc8a34f1004ecefc21","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.3.15","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"deb88ef1-602c-484d-8c69-e2da8c452e47","name":"WP Google Maps &lt;= 6.3.14 - Authenticated Stored Cross-Site Scripting (XSS) via CSRF","link":"https:\/\/wpscan.com\/vulnerability\/deb88ef1-602c-484d-8c69-e2da8c452e47","description":"The WP Google Maps WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) via CSRF security vulnerability.","date":null}],"impact":[]},{"uuid":"5ace6106fdf2d0fa1c2a4d763488f3df298df7a73027e514cd94efc1c12675fb","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"7.11.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a394c82c-83e2-40e9-a886-dcfb5abe9b7e","name":"WP Google Maps &lt;= 7.11.27 - Admin Settings CSRF","link":"https:\/\/wpscan.com\/vulnerability\/a394c82c-83e2-40e9-a886-dcfb5abe9b7e","description":"The WP Google Maps WordPress plugin was affected by an Admin Settings CSRF security vulnerability.","date":null}],"impact":[]},{"uuid":"4597906c96777b055fd8853ca31efdd84e7178f312a114e276ee6a232bec2494","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.28","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.28","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6627","name":"CVE-2023-6627","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6627","description":"[en] The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML\/Javascript on the site.","date":"2024-01-08"},{"id":"dfd67ca4cde9950247abdab4ba59671943af20f2","name":"WP Google Maps <= 9.0.27 - Unauthenticated Stored Cross-Site Scripting via REST API","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-9027-unauthenticated-stored-cross-site-scripting-via-rest-api","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 9.0.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2023-12-18"},{"id":"7d43d46f539d1996a4b5675f5092f8dee61adb0e","name":"WordPress  WP Google Maps Plugin  < 9.0.28 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-plugin-9-0-28-unauthenticated-stored-xss-vulnerability","description":"Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.28).\nMarc Montpas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 9.0.28.\nHave additional information or questions about this entry? Get in touch.","date":"2024-12-18"},{"id":"f5687d0e-98ca-4449-98d6-7170c97c8f54","name":"WP Go Maps &lt; 9.0.28 - Unauthenticated Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/f5687d0e-98ca-4449-98d6-7170c97c8f54","description":"The plugin does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML\/Javascript on the site.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"487d4c411d84e73a2c30b30e2f45d4d549fcf8dcc223da4c7a5665be27d35119","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.29","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.29","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6697","name":"CVE-2023-6697","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6697","description":"[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-01-24"},{"id":"41af1bc5b0f3123cc99dc50a5a93ddedcbd855a2","name":"WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-9028-reflected-cross-site-scripting","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-01-23"},{"id":"631eabf53598fc5168cbb2d4a713bd985a7a112a","name":"WordPress  WP Google Maps Plugin  <= 9.0.28 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-formerly-wp-google-maps-plugin-9-0-28-reflected-cross-site-scripting-vulnerability","description":"Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.29).\nNex Team discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 9.0.29.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-24"},{"id":"ffcebd9d-82fe-4a30-8ad6-cf6c03753d4c","name":"WP Go Maps (formerly WP Google Maps) &lt; 9.0.29 - Unauthenticated Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/ffcebd9d-82fe-4a30-8ad6-cf6c03753d4c","description":"The plugin is vulnerable to Reflected Cross-Site Scripting via the map id parameter due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2aecc54ce49f46851807ed37d1bc6efef4205e9d15e3b7eb24e365714711dab9","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.33","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.33","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-4839","name":"CVE-2023-4839","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-4839","description":"[en] The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-03-13"},{"id":"e68ad71782ee15278d291dc307c42b1a7abca4fa","name":"WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-9032-authenticated-administrator-stored-cross-site-scripting","description":"The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-03-12"},{"id":"79aac7364d1e22095f72a11406b1f334525a7f2a","name":"WordPress  WP Google Maps Plugin    <= 9.0.32 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-plugin-9-0-32-authenticated-administrator-stored-cross-site-scripting-vulnerability","description":"Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.33).\nMarco Wotschka - Wordfence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 9.0.33.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"d05a709a-5cf6-4d05-873e-6207eb36b319","name":"WP Go Maps &lt; 9.0.33 - Admin+ Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/d05a709a-5cf6-4d05-873e-6207eb36b319","description":"The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4275a91e3c40db907b491293e36f478761f9167bb4c88134a1a0fe5a18eca279","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.33","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.33","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1582","name":"CVE-2024-1582","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1582","description":"[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-13"},{"id":"5b3ffb540681b5bf9af9d74898a44fa6301faa0a","name":"WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-9032-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-03-12"},{"id":"6129d7473182eda679749716e3b81afee3426810","name":"WordPress  WP Google Maps Plugin    <= 9.0.32 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-formerly-wp-google-maps-plugin-9-0-32-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.33).\nRichard Telleng (stueotue) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 9.0.33.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"5ee9fe7c-f9b7-44b1-a32e-716f22196b71","name":"WP Go Maps (formerly WP Google Maps) &lt; 9.0.33 - Contributor+ Stored Cross-Site Scripting via Shortcode","link":"https:\/\/wpscan.com\/vulnerability\/5ee9fe7c-f9b7-44b1-a32e-716f22196b71","description":"The plugin is vulnerable to Stored Cross-Site Scripting via the plugin&#039;s &#039;wpgmza&#039; shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8fb3a526172eead46286bf470dbb183ace188979cb8c620f40152aa264c2dc8c","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.35","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.35","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-6777","name":"CVE-2023-6777","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-6777","description":"[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered by the plugin.","date":"2024-04-09"},{"id":"3905bbe1672dcc8ebb15fa2ec11ed1dc8a4bed6f","name":"WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-9034-information-exposure-to-potential-denial-of-service","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered by the plugin.","date":"2024-03-18"},{"id":"c3ccaf6dc6d2844eebc2819e8a6a54c0b5225847","name":"WordPress  WP Google Maps Plugin    <= 9.0.34 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-formerly-wp-google-maps-plugin-9-0-34-information-exposure-to-potential-denial-of-service-vulnerability","description":"Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.35).\nWordFence discovered and reported this Sensitive Data Exposure vulnerability in WordPress WP Google Maps Plugin.  This vulnerability has been fixed in version 9.0.35.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"ec563f4e-6972-4bd1-afe6-d2ec54c3236d","name":"WP Go Maps &lt; 9.0.35 - Information Exposure to Potential Denial of Service","link":"https:\/\/wpscan.com\/vulnerability\/ec563f4e-6972-4bd1-afe6-d2ec54c3236d","description":"The plugin is vulnerable to unauthenticated API key disclosure due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer&#039;s Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered by the plugin.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"l","score":"6.5","severity":"m","exploitable":"3.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"low","exploitable":"3.9","impact":"2.5"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"583453dbdd57a0be7fae1a10bc007c194d2096db5d741620078e7502dabf9b64","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.30","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.30","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-29931","name":"CVE-2024-29931","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-29931","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n\/a through <= 9.0.29.","date":"2024-03-27"},{"id":"577e708fe1b288cfce3b8c06ce1593062f25b578","name":"WordPress  WP Google Maps Plugin    <= 9.0.29 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-plugin-9-0-29-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.30).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 9.0.30.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"c9f9e0bbaa10af5aec2f69768a51408ec39a26b1","name":"WP Google Maps <= 9.0.29 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-google-maps-9029-reflected-cross-site-scripting","description":"The WP Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.0.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2024-03-25"},{"id":"03c3e0ab-3373-4ba6-90fb-a5245b0af34e","name":"WP Google Maps &lt; 9.0.30 - Reflected Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/03c3e0ab-3373-4ba6-90fb-a5245b0af34e","description":"The plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"047f767ae9225bdbd9eb18064239d6cabe60f1a7c4c2ffc3d17524fd7e005ca6","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.37","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.37","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3557","name":"CVE-2024-3557","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3557","description":"[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-24"},{"id":"44d8877853ea50bf21d6f365c1f8b0b9ae3e1add","name":"WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-9036-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2024-05-23"},{"id":"0bfe9ae2094d8c042e799d37fd10dd560c0ecde5","name":"WordPress WP Google Maps Plugin <= 9.0.36 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-formerly-wp-google-maps-plugin-9-0-36-authenticated-contributor-stored-cross-site-scripting-via-shortcode-vulnerability","description":"<p>WordPress WP Google Maps Plugin <= 9.0.36 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: WP Google Maps<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-google-maps\/#developers<\/p><p>Affected Version <= 9.0.36<\/p><p>Fixed in version 9.0.37 <\/p>","date":"2024-05-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."},{"cwe":"CWE-80","name":"Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","description":"The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as \"<\", \">\", and \"&\" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1f82bd98922abab0961b77ea55acd673e1995c7a0f378a06742eae55e584ee11","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.39","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-5994","name":"CVE-2024-5994","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-5994","description":"[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Version 9.0.39 adds a caution to make administrators aware of the possibility for abuse if permissions are granted to lower-level users.","date":"2024-06-14"},{"id":"b15c648aa8c6e4571804c59920c6ce6e771c4a10","name":"WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-9038-authenticated-contributor-stored-cross-site-scripting","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Version 9.0.39 adds a caution to make administrators aware of the possibility for abuse if permissions are granted to lower-level users.","date":"2024-06-13"},{"id":"56801b42ebc15c8fc9e41174b67eea3ed733d37e","name":"WordPress WP Google Maps Plugin <= 9.0.38 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-plugin-9-0-38-authenticated-stored-cross-site-scripting-vulnerability","description":"<p>WordPress WP Google Maps Plugin <= 9.0.38 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: WP Google Maps<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-google-maps\/#developers<\/p><p>Affected Version <= 9.0.38<\/p><p>Fixed in version 9.0.39 <\/p>","date":"2024-06-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3a921a6d7e62a6fe9cf635e586569320a226068bab838231fa35afa3f30f4184","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.39","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f6378e7eeb13a6d95b5e433138bee09cfb992894","name":"WordPress WP Google Maps Plugin <= 9.0.38 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-go-maps-plugin-9-0-38-authenticated-contributor-stored-cross-site-scripting-vulnerability","description":"<p>WordPress WP Google Maps Plugin <= 9.0.38 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: WP Google Maps<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wp-google-maps\/#developers<\/p><p>Affected Version <= 9.0.38<\/p><p>Fixed in version 9.0.39 <\/p>","date":"2024-06-14"}],"impact":[]},{"uuid":"f8ede0dbd4d15a583ac6f999c0cb37031697c6eb4b46c45dec9b9807268294cb","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.41","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.41","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-24742","name":"CVE-2025-24742","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-24742","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n\/a through <= 9.0.40.","date":"2025-01-27"},{"id":"fe83aec87f0be34afcba97a24352bdb3a72092c8","name":"WordPress WP Go Maps Plugin <= 9.0.40 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wp-google-maps\/vulnerability\/wordpress-wp-google-maps-plugin-9-0-40-cross-site-request-forgery-csrf-vulnerability","description":"<p>WordPress WP Go Maps Plugin <= 9.0.40 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: WP Go Maps<\/p><p>Fixed in version 9.0.41 <\/p><p>Affected Version <= 9.0.40<\/p><p>CVE: CVE-2025-24742<\/p>","date":"2025-01-24"},{"id":"ebc1aec067d1330f5a5c714bd08639d8ace50bad","name":"WP Go Maps <= 9.0.40 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-9040-cross-site-request-forgery","description":"The WP Go Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.40. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2025-01-24"},{"id":"EUVD-2025-3932","name":"EUVD-2025-3932","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-3932","description":"Cross-Site Request Forgery (CSRF) vulnerability in WP Go Maps (formerly WP Google Maps) WP Go Maps. This issue affects WP Go Maps: from n\/a through 9.0.40.","date":"2025-01-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"22c9f3ba165d070241f1a70396c14b7c486cff99a080420260d111afbc343ee7","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.47","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11166","name":"CVE-2025-11166","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11166","description":"[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic reachable via GET requests with no permission_callback. This makes it possible for unauthenticated attackers to force logged-in administrators to create, update, or delete markers and geometry features via CSRF attacks, and allows anonymous users to trigger mass deletion of markers via unsafe GET requests.","date":"2025-10-09"},{"id":"7e8e17edcaa8c480ca0d51049646feb0a85f2cc3","name":"WP Go Maps (formerly WP Google Maps) <= 9.0.46 - Cross-Site Request Forgery to Plugin Settings Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-9046-cross-site-request-forgery-to-plugin-settings-update","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic reachable via GET requests with no permission_callback. This makes it possible for unauthenticated attackers to force logged-in administrators to create, update, or delete markers and geometry features via CSRF attacks, and allows anonymous users to trigger mass deletion of markers via unsafe GET requests.","date":"2025-10-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7e5dbd1eb99ac5ada7b9e81cbd4de1771d1907ca9f7bbe7ca070664ed0b32e8f","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.49","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.49","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11703","name":"CVE-2025-11703","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11703","description":"[en] The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.","date":"2025-10-18"},{"id":"EUVD-2025-34978","name":"EUVD-2025-34978","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-34978","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.","date":"2025-10-18"},{"id":"ca3b704122f8988e0ea550ba5a5c7f1421936525","name":"WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-9048-unauthenticated-cache-poisoning","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.","date":"2025-10-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-349","name":"Acceptance of Extraneous Untrusted Data With Trusted Data","description":"The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a9929eef5436293c07d5d57377638daf96c4c4f637d072576231868574f6a57a","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.48","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"9.0.48","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-11307","name":"CVE-2025-11307","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-11307","description":"[en] The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.","date":"2025-11-11"},{"id":"8d2c64871c4195477d3fc401bf510c6e37d7c84a","name":"Google Maps <= 9.0.47 - Unauthenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/google-maps-9047-unauthenticated-stored-cross-site-scripting","description":"The Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-10-21"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"156ee478ba6b606c08883cb18812c9c497b34725fd77f626cd032d7391ced2c3","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.06","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.0.06","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4268","name":"WP Go Maps (formerly WP Google Maps) <= 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4268","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018wpgmza_custom_js\u2019 parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings' hook anonymous function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"a8c11b95843b750c8372c45ed3fac214218251d1","name":"WP Go Maps (formerly WP Google Maps) <= 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-10005-missing-authorization-to-authenticated-subscriber-stored-cross-site-scripting-via-admin-post-wpgmza-save-settings","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018wpgmza_custom_js\u2019 parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings' hook anonymous function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2026-03-17"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"cc662c7d7f55a19afc08cfa635030c473ceb7a412948ba2609d12de804472e95","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.05","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.0.05","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-0593","name":"WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0593","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.","date":"0000-00-00"},{"id":"EUVD-2026-4540","name":"EUVD-2026-4540","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-4540","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.","date":"2026-01-24"},{"id":"39ee8b2415be2f303b5dd259afef2b01c49b9716","name":"WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-formerly-wp-google-maps-10004-missing-authorization-to-authenticated-subscriber-map-engine-setting-modification","description":"The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.","date":"2026-01-24"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":null,"impact":null}}},{"uuid":"d7d97951d99d68e408a1850cba2f4bc506ea1cc2186782c4e1a276f9db867c09","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.0.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-8385","name":"CVE-2026-8385","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-8385","description":"[en] The WP Go Maps  WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.","date":"2026-06-15"},{"id":"30f10bf688aeb85614c9b2254c043f9e19375d5e","name":"WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/de64e79f-0284-4d23-a18b-64554f2b188e","description":"The WP Go Maps plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.0.09 via the datatables AJAX fallback route. This makes it possible for unauthenticated attackers to extract  marker records that the site owner has not approved for public display, including their title, category, address and description fields.","date":"2026-06-05"},{"id":"11ace3cf273175c422435426e02d0a7aaee6b438","name":"WP Go Maps &lt; 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-10010-unauthenticated-sensitive-information-disclosure-via-datatables-ajax-fallback","description":"The WP Go Maps plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.0.09 via the datatables AJAX fallback route. This makes it possible for unauthenticated attackers to extract marker records that the site owner has not approved for public display, including their title, category, address and description fields.","date":null}],"impact":{"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"55d183742cb6ad0ac5cf06fe687f552bc5338d1515a9a3650e3b39d21abeff4f","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.0.10","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-8386","name":"CVE-2026-8386","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-8386","description":"[en] The WP Go Maps  WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.","date":"2026-06-15"}],"impact":{"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"56951c4bf2ca922b18e309ea7a06450e4a01540e8d4ccaa2a9b9f69bfccb4213","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.1.02","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12238","name":"CVE-2026-12238","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12238","description":"[en] The WP Go Maps \u2013 Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary records in plugin database tables (maps, markers, circles, polygons, polylines, rectangles, and point labels) by supplying a WPGMZA-namespaced CRUD-backed class name via the phpClass parameter. The namespace validation check (requiring the 'WPGMZA' prefix) does not prevent exploitation because classes such as WPGMZA\\Map and WPGMZA\\Marker satisfy it while still triggering an INSERT into the corresponding plugin table before the route rejects the request.","date":"2026-06-19"},{"id":"e12b4eb4b574bdf3f4c3c97b7f138c74c98739b7","name":"WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/c51c6cfb-9a79-4190-87ff-7eddb866ae56","description":"The WP Go Maps \u2013 Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary records in plugin database tables (maps, markers, circles, polygons, polylines, rectangles, and point labels) by supplying a WPGMZA-namespaced CRUD-backed class name via the phpClass parameter. The namespace validation check (requiring the 'WPGMZA' prefix) does not prevent exploitation because classes such as WPGMZA\\Map and WPGMZA\\Marker satisfy it while still triggering an INSERT into the corresponding plugin table before the route rejects the request.","date":"2026-06-19"},{"id":"df41b80cae76d70e8f57e6f3a3a66344623e8a74","name":"WP Go Maps &lt;= 10.1.01 - Unauthenticated Arbitrary Record Creation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-10101-unauthenticated-arbitrary-record-creation","description":"The WP Go Maps \u2013 Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary records in plugin database tables (maps, markers, circles, polygons, polylines, rectangles, and point labels) by supplying a WPGMZA-namespaced CRUD-backed class name via the phpClass parameter. The namespace validation check (requiring the &#039;WPGMZA&#039; prefix) does not prevent exploitation because classes such as WPGMZA\\Map and WPGMZA\\Marker satisfy it while still triggering an INSERT into the corresponding plugin table before the route rejects the request.","date":null},{"id":"EUVD-2026-38063","name":"EUVD-2026-38063","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-38063","description":"The WP Go Maps \u2013 Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary records in plugin database tables (maps, markers, circles, polygons, polylines, rectangles, and point labels) by supplying a WPGMZA-namespaced CRUD-backed class name via the phpClass parameter. The namespace validation check (requiring the 'WPGMZA' prefix) does not prevent exploitation because classes such as WPGMZA\\Map and WPGMZA\\Marker satisfy it while still triggering an INSERT into the corresponding plugin table before the route rejects the request.","date":"2026-06-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7454ef050bf7608d6617fc1eb762c5fecf618134ea26509ed211c86d17ec2c93","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.06","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.1.06","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25466","name":"WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25466","description":"Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.","date":"0000-00-00"},{"id":"b47c03336328b504b7ac2edafa9b8aa7f28dcdf5","name":"WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map <= 10.1.05 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/daa5e6a7-91ff-4dd0-aec2-f9a13e38f309","description":"The WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 10.1.05. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-07-22"},{"id":"9a86f131395fd6f1d49355ea277f9861724ece04","name":"WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map <= 10.1.05 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-google-map-openstreetmap-leaflet-map-10105-missing-authorization","description":"The WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 10.1.05. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-06-19"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"613eb01e0f838c24e6473d328491765a713d7ad4fd4cdc58fb6b574e7317ed33","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.04","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.1.04","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15381","name":"CVE-2026-15381","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15381","description":"[en] The WP Go Maps  WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.","date":"2026-07-31"},{"id":"c9f4dbad154f2234e5a690bfbd972541a5b81482","name":"WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map < 10.1.04 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/74a566ea-fffc-4e7e-b6bf-086aeb5b7ce1","description":"The WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to SQL Injection in versions up to 10.1.04 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-08-04"},{"id":"213cc7facf5c1172fef8f394d5306a60b1e4e9d8","name":"WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map < 10.1.04 - Unauthenticated SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-google-map-openstreetmap-leaflet-map-10104-unauthenticated-sql-injection","description":"The WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to SQL Injection in versions up to 10.1.04 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-07-22"}],"impact":{"cwe":[{"cwe":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","description":"The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a6f44a1a1d10363e550fefd65e4662b7292879750d91386dbcc66b0f8dd848ee","name":"WP Go Maps &#8211; Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.09","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"10.1.09","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-84780","name":"CVE-2026-84780","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-84780","description":"[en] Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.","date":"2026-09-02"},{"id":"cb993030b7df3f947cdf963452a84f9ccadcd1cd","name":"WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map <= 10.1.08 - Unauthenticated Denial of Service","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-google-maps\/wp-go-maps-google-map-openstreetmap-leaflet-map-10108-unauthenticated-denial-of-service","description":"The WP Go Maps \u2013 Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 10.1.08. This is due to insufficient validation of user supplied input. This makes it possible for unauthenticated attackers to make the affected site unavailable.","date":"2026-08-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"l","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:L","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-770","name":"Allocation of Resources Without Limits or Throttling","description":"The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789024847"}