VendorsCodeCabinwp_go_mapsany version
Vulnerabilities

CodeCabin WP Go Maps any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2019-10692
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
Published 2019-04-02 · Modified
9.8EPSS 0.787
CVE-2025-24742
WordPress WP Google Maps plugin <= 9.0.40 - Cross Site Request Forgery (CSRF) vulnerability
Published 2025-01-27 · Modified
8.8EPSS 0.002
CVE-2024-29931
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
Published 2024-03-27 · Modified
7.1EPSS 0.008
CVE-2023-6777
WP Go Maps (formerly WP Google Maps) <= 9.0.34 - Information Exposure to Potential Denial of Service
Published 2024-04-09 · Modified
6.5EPSS 0.008
CVE-2022-47595
WordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path Traversal
Published 2023-03-14 · Modified
6.5EPSS 0.008
CVE-2024-5994
WP Go Maps (formerly WP Google Maps) <= 9.0.38 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-06-14 · Modified
6.4EPSS 0.004
CVE-2024-3557
WP Go Maps (formerly WP Google Maps) <= 9.0.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-05-24 · Modified
6.4EPSS 0.003
CVE-2024-1582
WP Go Maps (formerly WP Google Maps) <= 9.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Published 2024-03-13 · Modified
6.4EPSS 0.003
CVE-2019-9912
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
Published 2019-03-21 · Modified
6.1EPSS 0.032
CVE-2023-6627
WP Go Maps < 9.0.28 - Unauthenticated Stored XSS
Published 2024-01-08 · Modified
6.1EPSS 0.006
CVE-2021-36870
WordPress WP Google Maps plugin <= 8.1.12 - Multiple Authenticated Persistent XSS vulnerabilities
Published 2021-09-09 · Modified
5.5EPSS 0.006
CVE-2021-36871
WordPress WP Google Maps Pro premium plugin <= 8.1.11 - Multiple Authenticated Persistent XSS vulnerabilities
Published 2021-09-09 · Modified
5.5EPSS 0.006
CVE-2021-24383
WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)
Published 2021-06-21 · Modified
5.41 PoCEPSS 0.025
CVE-2019-14792
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
Published 2019-08-09 · Modified
5.4EPSS 0.011
CVE-2023-4839
WP Go Maps <= 9.0.32 - Authenticated (Administrator+) Stored Cross-Site Scripting
Published 2024-03-13 · Modified
4.8EPSS 0.003
CVE-2014-7182
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.
Published 2014-10-22 · Modified
4.3EPSS 0.025