WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters
Minimum safe version
4.9.2
Update to 4.9.2 or later to address 26 fixable vulnerabilities
CVE-2025-13364
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection
WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter
CVE-2025-12062
CVE-2025-67535
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WordPress WP Google Map Plugin Plugin < 4.7.2 is vulnerable to Cross Site Scripting (XSS)
WordPress WP Google Map Plugin Plugin <= 4.6.1 is vulnerable to SQL Injection
WP Google Map Plugin < 3.0.0 - CSRF to Authenticated Cross-Site Scripting (XSS)
WP Google Map Plugin < 4.1.0 - CSRF to Unauthenticated PHP Object Injection
CVE-2023-28172
CVE-2023-23878
WP Google Map Plugin < 3.0.0 - Cross-Site Request Forgery to Cross-Site Scripting
WP Google Map Plugin <= 4.0.9 - Cross-Site Request Forgery to PHP Object Injection
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.0.9 - Reflected Cross-Site Scripting
WordPress WP Google Map Plugin <= 4.1.3 - Authenticated SQL Injection (SQLi) vulnerability
CVE-2018-0577
CVE-2015-9305
CVE-2016-10878
CVE-2015-9308
CVE-2015-9307
CVE-2015-9309
CVE-2021-24130
CVE-2022-25600