VendorsWEPLUGINSwp_mapsall versions
Vulnerabilities

WEPLUGINS WP Maps

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2015-9307
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
Published 2019-08-14 · Modified
8.8EPSS 0.007
CVE-2015-9308
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
Published 2019-08-14 · Modified
8.8EPSS 0.007
CVE-2015-9309
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
Published 2019-08-14 · Modified
8.8EPSS 0.007
CVE-2022-25600
WordPress WP Google Map plugin <= 4.2.3 - Cross-Site Request Forgery (CSRF) vulnerability
Published 2022-03-11 · Modified
8.8EPSS 0.006
CVE-2023-28172
WordPress WP Google Map Plugin Plugin <= 4.4.2 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-11-12 · Modified
8.8EPSS 0.003
CVE-2021-24130
WP Google Map Plugin < 4.1.5 - Authenticated SQL Injection
Published 2021-03-18 · Modified
7.2EPSS 0.014
CVE-2015-9305
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
Published 2019-08-12 · Modified
6.1EPSS 0.010
CVE-2016-10878
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
Published 2019-08-12 · Modified
6.1EPSS 0.010
CVE-2023-23878
WordPress WP Google Map Plugin Plugin <= 4.3.9 is vulnerable to Cross Site Scripting (XSS)
Published 2023-04-04 · Modified
5.9EPSS 0.004
CVE-2021-24502
WP Google Map < 1.7.7 - Authenticated Stored Cross-Site Scripting (XSS)
Published 2021-08-09 · Modified
4.8EPSS 0.007
CVE-2025-3502
WP Maps < 4.7.2 - Admin+ Stored XSS
Published 2025-05-01 · Analyzed
4.8EPSS 0.003
CVE-2025-3503
WP Maps < 4.7.2 - Admin+ Stored XSS
Published 2025-05-01 · Analyzed
4.8EPSS 0.003
CVE-2025-3504
WP Maps < 4.7.2 - Admin+ Stored XSS
Published 2025-05-01 · Analyzed
4.8EPSS 0.003