Extension WordPress
Vulnérabilités WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
Cette page rassemble les failles publiées pour WP Go Maps – Google Map, OpenStreetMap, Leaflet Map, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Go Maps – Google Map, OpenStreetMap, Leaflet Map
25 fiches
WP Go Maps <= 10.1.01 – Unauthenticated Arbitrary Record Creation
The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is…
*-10.1.01
10.1.02
19/06/2026
WP Go Maps < 10.0.10 – Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback
The WP Go Maps plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.0.09 via the datatables AJAX fallback route. This makes it possible for unauthenticated attackers to extract marker records…
*-10.0.09
10.0.10
05/06/2026
WP Go Maps (formerly WP Google Maps) <= 10.0.05 – Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and…
*-10.0.05
10.0.06
17/03/2026
WP Go Maps (formerly WP Google Maps) <= 10.0.04 – Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes…
*-10.0.04
10.0.05
24/01/2026
Google Maps <= 9.0.47 – Unauthenticated Stored Cross-Site Scripting
The Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-9.0.47
9.0.48
21/10/2025
WP Go Maps (formerly WP Google Maps) <= 9.0.48 – Unauthenticated Cache Poisoning
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and…
*-9.0.48
9.0.49
17/10/2025
WP Go Maps (formerly WP Google Maps) <= 9.0.46 – Cross-Site Request Forgery to Plugin Settings Update
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an…
*-9.0.46
9.0.47
08/10/2025
WP Go Maps <= 9.0.40 – Cross-Site Request Forgery
The WP Go Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.40. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated…
*-9.0.40
9.0.41
24/01/2025
WP Go Maps (formerly WP Google Maps) <= 9.0.38 – Authenticated (Contributor+) Stored Cross-Site Scripting
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been…
*-9.0.38
9.0.39
13/06/2024
WP Go Maps (formerly WP Google Maps) <= 9.0.36 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping…
*-9.0.36
9.0.37
23/05/2024
WP Google Maps <= 9.0.29 – Reflected Cross-Site Scripting
The WP Google Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.0.29 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-9.0.29
9.0.30
25/03/2024
WP Go Maps (formerly WP Google Maps) <= 9.0.34 – Information Exposure to Potential Denial of Service
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This…
*-9.0.34
9.0.35
18/03/2024
WP Go Maps (formerly WP Google Maps) <= 9.0.32 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping…
*-9.0.32
9.0.33
12/03/2024
WP Go Maps <= 9.0.32 – Authenticated (Administrator+) Stored Cross-Site Scripting
The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-9.0.32
9.0.33
12/03/2024
WP Go Maps (formerly WP Google Maps) <= 9.0.28 – Reflected Cross-Site Scripting
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping.…
*-9.0.28
9.0.29
23/01/2024
WP Google Maps <= 9.0.27 – Unauthenticated Stored Cross-Site Scripting via REST API
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to, and including, 9.0.27 due to insufficient input sanitization and output escaping. This…
*-9.0.27
9.0.28
18/12/2023
WP Go Maps <= 9.0.15 – Authenticated (Admin+) Directory Traversal
The WP Go Maps plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.0.15 via the 'wpgmza_xml_location' option accessed in 'getXMLCacheDirPath'. This allows administrator-level attackers to read the contents of arbitrary files on…
*-9.0.15
9.0.16
20/01/2023
WP Google Maps <= 8.1.12 – Authenticated Stored Cross-Site Scripting
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions
[*, 8.1.13)
8.1.13
08/09/2021
WP Google Maps <= 8.1.11 – Authenticated Stored Cross-Site Scripting
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
[*, 8.1.12)
8.1.12
07/06/2021
WP Go Maps (formerly WP Google Maps) <= 7.11.17 – SQL Injection
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
*-7.11.17
7.11.18
09/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.