cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwp-google-map-plugin wp-google-map-plugin

Direction: ascending
Jun 07, 2024

WordPress Plugin for Google Maps – WP MAPS # CVE-2015-9305

CVE, Research URL

CVE-2015-9305

Date
Aug 12, 2019
Research Description
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps – WP MAPS # CVE-2022-25600

CVE, Research URL

CVE-2022-25600

Date
Mar 11, 2022
Research Description
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2021-24130

CVE, Research URL

CVE-2021-24130

Date
Mar 18, 2021
Research Description
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2015-9309

CVE, Research URL

CVE-2015-9309

Date
Aug 14, 2019
Research Description
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2015-9308

CVE, Research URL

CVE-2015-9308

Date
Aug 14, 2019
Research Description
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2016-10878

CVE, Research URL

CVE-2016-10878

Date
Aug 12, 2019
Research Description
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2018-0577

CVE, Research URL

CVE-2018-0577

Date
May 14, 2018
Research Description
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2023-23878

CVE, Research URL

CVE-2023-23878

Date
Apr 04, 2023
Research Description
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2023-28172

CVE, Research URL

CVE-2023-28172

Date
Nov 13, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2015-9307

CVE, Research URL

CVE-2015-9307

Date
Aug 14, 2019
Research Description
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
Affected versions
Min -, max -.
Status
vulnerable
Jul 01, 2024

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2024-2386

CVE, Research URL

CVE-2024-2386

Date
Jun 29, 2024
Research Description
The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
Min -, max -.
Status
vulnerable
May 07, 2025

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2025-3503

CVE, Research URL

CVE-2025-3503

Date
May 01, 2025
Research Description
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable

WordPress Plugin for Google Maps &#8211; WP MAPS # CVE-2025-3502

CVE, Research URL

CVE-2025-3502

Date
May 01, 2025
Research Description
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
Min -, max -.
Status
vulnerable