Extension WordPress
Vulnérabilités WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters
Cette page rassemble les failles publiées pour WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters
25 fiches
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters < 4.9.3 – Authenticated (Subscriber+) Local File Inclusion
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in versions up to 4.9.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and…
[*, 4.9.3)
4.9.3
11/06/2026
WP Maps <= 4.9.4 – Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping.…
*-4.9.4
4.9.5
05/06/2026
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and…
*-4.8.7
4.8.8
15/04/2026
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 – Unauthenticated SQL Injection
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-4.9.1
4.9.2
08/04/2026
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 – Unauthenticated SQL Injection via 'orderby' Parameter
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied…
*-4.9.1
4.9.2
22/03/2026
WP Maps <= 4.9.1 – Unauthenticated SQL Injection via 'location_id' Parameter
The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input…
*-4.9.1
4.9.2
10/03/2026
WP Maps <= 4.8.6 – Authenticated (Subscriber+) Limited Local File Inclusion
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, with…
*-4.8.6
4.8.7
16/02/2026
Maps <= 4.8.6 – Authenticated (Administrator+) PHP Object Injection
The Maps plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a…
*-4.8.6
4.8.7
02/11/2025
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping.…
*-4.7.1
4.7.2
10/04/2025
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping.…
*-4.7.1
4.7.2
10/04/2025
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 – Authenticated (Admin+) Stored Cross-Site Scripting
The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping.…
*-4.7.1
4.7.2
10/04/2025
WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 – Authenticated (Contributor+) SQL Injection
The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on…
*-4.6.1
4.6.2
28/06/2024
WP Google Map Plugin <= 4.4.2 – Cross-Site Request Forgery via delete()
The WP Google Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.2. This is due to missing or incorrect nonce validation on the delete() function of the WPGMP_Model_Group_Map, WPGMP_Model_Location,…
*-4.4.2
4.4.3
13/03/2023
WP MAPS <= 4.3.9 – Authenticated (Editor+) Stored Cross-Site Scripting
The WP MAPS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 4.3.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-4.3.9
4.4.0
20/01/2023
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.2.3 – Cross-Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions
[*, 4.2.4)
4.2.4
22/02/2022
WP Google Map Plugin <= 4.1.4 – Authenticated SQL Injection via Orderby
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
*-4.1.4
4.1.5
25/11/2020
WP Google Map Plugin <= 4.0.9 – Cross-Site Request Forgery to PHP Object Injection
The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.0. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for…
[*, 4.1.0)
4.1.0
21/09/2019
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.0.9 – Reflected Cross-Site Scripting
The WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wp_ajax_fc_geocoding AJAX aciton in versions up to, and including, 4.0.9 due to insufficient input…
*-4.0.9
4.1.0
21/09/2019
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps < 4.0.4 – Cross-Site Scripting
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
[*, 4.0.4)
4.0.4
27/04/2018
WP Google Map Plugin <= 3.1.1 – Cross-Site Scripting
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
[*, 3.1.2)
3.1.2
27/07/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.