Weplugins Wp Maps vulnerabilities

13 known vulnerabilities affecting weplugins/wp_maps.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-3504MEDIUMCVSS 4.8fixed in 4.7.22025-05-01
CVE-2025-3504 [MEDIUM] CWE-79 CVE-2025-3504: The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, wh The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2025-3503MEDIUMCVSS 4.8fixed in 4.7.22025-05-01
CVE-2025-3503 [MEDIUM] CWE-79 CVE-2025-3503: The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, wh The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2025-3502MEDIUMCVSS 4.8fixed in 4.7.22025-05-01
CVE-2025-3502 [MEDIUM] CWE-79 CVE-2025-3502: The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, wh The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
nvd
CVE-2023-28172HIGHCVSS 8.8≤ 4.4.22023-11-12
CVE-2023-28172 [MEDIUM] CWE-352 CVE-2023-28172: Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
nvd
CVE-2023-23878MEDIUMCVSS 5.4fixed in 4.4.02023-04-04
CVE-2023-23878 [MEDIUM] CWE-79 CVE-2023-23878: Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
nvd
CVE-2022-25600HIGHCVSS 8.8fixed in 4.2.42022-03-11
CVE-2022-25600 [MEDIUM] CWE-352 CVE-2022-25600: Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Co Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
nvd
CVE-2021-24502MEDIUMCVSS 4.8fixed in 1.7.72021-08-09
CVE-2021-24502 [MEDIUM] CWE-79 CVE-2021-24502: The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outp The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
nvd
CVE-2021-24130HIGHCVSS 7.2fixed in 4.1.52021-03-18
CVE-2021-24130 [HIGH] CWE-89 CVE-2021-24130: Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
nvd
CVE-2015-9307HIGHCVSS 8.8fixed in 2.3.102019-08-14
CVE-2015-9307 [HIGH] CWE-352 CVE-2015-9307: The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location featur The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
nvd
CVE-2015-9308HIGHCVSS 8.8fixed in 2.3.102019-08-14
CVE-2015-9308 [HIGH] CWE-352 CVE-2015-9308: The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
nvd
CVE-2015-9309HIGHCVSS 8.8fixed in 2.3.102019-08-14
CVE-2015-9309 [HIGH] CWE-352 CVE-2015-9309: The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category featur The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
nvd
CVE-2015-9305MEDIUMCVSS 6.1fixed in 2.3.72019-08-12
CVE-2015-9305 [MEDIUM] CWE-79 CVE-2015-9305: The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() an The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
nvd
CVE-2016-10878MEDIUMCVSS 6.1fixed in 3.1.22019-08-12
CVE-2016-10878 [MEDIUM] CWE-79 CVE-2016-10878: The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
nvd