Home/Product/codecabin wp go maps
Product

codecabin wp go maps

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-24742
< 9.0.41
Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a throu
4.3MEDIUM
CVE-2024-5994
< 9.0.39
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in
6.4MEDIUM
CVE-2024-3557
< 9.0.37
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza
6.4MEDIUM
CVE-2023-6777
< 9.0.35
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up t
5.3MEDIUM
CVE-2024-29931
< 9.0.30
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google
7.1HIGH
CVE-2024-1582
< 9.0.33
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmz
6.4MEDIUM
CVE-2023-4839
< 9.0.33
The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0
4.4MEDIUM
CVE-2023-6697
<= 9.0.28
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id param
6.1MEDIUM
CVE-2023-6627
< 9.0.28
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, whi
6.1MEDIUM
CVE-2022-47595
<= 9.0.15
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Map
4.9MEDIUM
CVE-2021-36871
<= 8.1.11
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versi
5.5MEDIUM
CVE-2021-36870
<= 8.1.12
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.1
5.5MEDIUM
CVE-2021-24383
< 8.1.12
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of
5.4MEDIUM
CVE-2019-14792
< 7.11.35
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
5.4MEDIUM
CVE-2019-10692
< 7.11.18
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field nam
9.8CRITICAL
CVE-2019-9912
< 7.10.43
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
6.1MEDIUM
CVE-2014-7182
<= 6.0.26
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attacker
threatengine.sh