Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

WP Go Maps (formerly WP Google Maps) — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in WP Go Maps (formerly WP Google Maps), with AI-generated Chinese analysis, references, and POCs.

This page documents common vulnerabilities affecting the WP Go Maps WordPress plugin, previously known as WP Google Maps, focusing on weakness types such as Cross-Site Scripting, Broken Access Control, and Injection flaws. It aggregates security advisories, patches, and vulnerability reports published by the vendor and third-party security researchers covering incidents from January 2015 through the present. By maintaining a comprehensive timeline of these security events, the resource ensures transparency regarding the plugin’s historical security posture and the frequency of discovered flaws. Readers can use this collection to track the vendor’s response to critical issues, understand the prevalence of specific weakness classes within this codebase, and examine the full vulnerability history of the product over time. This information is intended to help system administrators, developers, and security auditors assess the risk associated with deploying WP Go Maps in their environments. The data highlights recurring patterns in plugin development, such as inadequate input sanitization and improper output escaping, which have led to significant security breaches. Users seeking to evaluate the long-term reliability of the software can review how past vulnerabilities were mitigated and whether similar issues persist in current versions. This page serves as a centralized reference point for understanding the security implications of using this specific mapping solution without resorting to external, fragmented sources.

Vendor: WP Go Maps

CVE IDTitleCVSSSeverityPublished
CVE-2026-4268 WP Go Maps (formerly WP Google Maps) <= 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings CWE-79 6.4 Medium2026-03-18
CVE-2026-0593 WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification CWE-862 5.3 Medium2026-01-24
CVE-2025-11307 WP Google Maps < 9.0.48 - Unauthenticated Stored XSS 6.1 -2025-11-11
CVE-2025-11703 WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning CWE-349 5.3 Medium2025-10-18
CVE-2025-11166 WP Go Maps (formerly WP Google Maps) <= 9.0.46 - Cross-Site Request Forgery to Plugin Settings Update CWE-352 5.4 Medium2025-10-09
CVE-2024-5994 WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting CWE-79 6.4 Medium2024-06-14
CVE-2024-3557 WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2024-05-24
CVE-2023-6777 WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service CWE-200 5.3 Medium2024-04-09
CVE-2024-1582 WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2024-03-13
CVE-2023-4839 WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scripting CWE-79 4.4 Medium2024-03-13
CVE-2023-6697 WP Go Maps (formerly WP Google Maps) <= 9.0.28 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2024-01-24
CVE-2023-6627 WP Go Maps < 9.0.28 - Unauthenticated Stored XSS 6.1AIMediumAI2024-01-08
CVE-2022-47595 WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversal CWE-22 4.9 Medium2023-03-14

All 13 known CVE vulnerabilities affecting WP Go Maps (formerly WP Google Maps) with full Chinese analysis, references, and POCs where available.