Extension WordPress

Vulnérabilités WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

Cette page rassemble les failles publiées pour WP Go Maps – Google Map, OpenStreetMap, Leaflet Map, leurs plages de versions affectées et les correctifs signalés dans la base locale.

25Vulnérabilités
1Critiques
25Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

25 fiches

CVE-2026-8385 Moyenne · 5,3
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps < 10.0.10 – Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback

The WP Go Maps plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.0.09 via the datatables AJAX fallback route. This makes it possible for unauthenticated attackers to extract marker records…

Versions affectées

*-10.0.09

Correctif

10.0.10

Publication

05/06/2026

CVE-2026-4268 Moyenne · 6,4
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 10.0.05 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and…

Versions affectées

*-10.0.05

Correctif

10.0.06

Publication

17/03/2026

CVE-2026-0593 Moyenne · 5,3
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 10.0.04 – Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes…

Versions affectées

*-10.0.04

Correctif

10.0.05

Publication

24/01/2026

CVE-2025-11307 Élevée · 7,2
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

Google Maps <= 9.0.47 – Unauthenticated Stored Cross-Site Scripting

The Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-9.0.47

Correctif

9.0.48

Publication

21/10/2025

CVE-2025-11166 Moyenne · 5,4
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 9.0.46 – Cross-Site Request Forgery to Plugin Settings Update

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an…

Versions affectées

*-9.0.46

Correctif

9.0.47

Publication

08/10/2025

CVE-2024-5994 Moyenne · 6,4
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 9.0.38 – Authenticated (Contributor+) Stored Cross-Site Scripting

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been…

Versions affectées

*-9.0.38

Correctif

9.0.39

Publication

13/06/2024

CVE-2024-3557 Moyenne · 6,4
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 9.0.36 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping…

Versions affectées

*-9.0.36

Correctif

9.0.37

Publication

23/05/2024

CVE-2024-29931 Moyenne · 6,1
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Google Maps <= 9.0.29 – Reflected Cross-Site Scripting

The WP Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.0.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

*-9.0.29

Correctif

9.0.30

Publication

25/03/2024

CVE-2023-6777 Moyenne · 5,3
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 9.0.34 – Information Exposure to Potential Denial of Service

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This…

Versions affectées

*-9.0.34

Correctif

9.0.35

Publication

18/03/2024

CVE-2024-1582 Moyenne · 6,4
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 9.0.32 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping…

Versions affectées

*-9.0.32

Correctif

9.0.33

Publication

12/03/2024

CVE-2023-4839 Moyenne · 4,4
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps <= 9.0.32 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

Versions affectées

*-9.0.32

Correctif

9.0.33

Publication

12/03/2024

CVE-2023-6697 Moyenne · 6,1
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps (formerly WP Google Maps) <= 9.0.28 – Reflected Cross-Site Scripting

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping.…

Versions affectées

*-9.0.28

Correctif

9.0.29

Publication

23/01/2024

CVE-2023-6627 Moyenne · 6,1
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Google Maps <= 9.0.27 – Unauthenticated Stored Cross-Site Scripting via REST API

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 9.0.27 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-9.0.27

Correctif

9.0.28

Publication

18/12/2023

CVE-2022-47595 Moyenne · 4,9
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map

WP Go Maps <= 9.0.15 – Authenticated (Admin+) Directory Traversal

The WP Go Maps plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.0.15 via the 'wpgmza_xml_location' option accessed in 'getXMLCacheDirPath'. This allows administrator-level attackers to read the contents of arbitrary files on…

Versions affectées

*-9.0.15

Correctif

9.0.16

Publication

20/01/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités