WP Go Maps (formerly WP Google Maps) <= 10.0.04 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification
WP Go Maps (formerly WP Google Maps)
Minimum safe version
10.0.06
Update to 10.0.06 or later to address 32 fixable vulnerabilities
WP Go Maps (formerly WP Google Maps) <= 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings
CVE-2025-11307
CVE-2025-11703
CVE-2025-11166
CVE-2025-24742
WordPress WP Google Maps Plugin <= 9.0.38 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-5994
CVE-2024-3557
CVE-2024-29931
CVE-2023-6777
CVE-2024-1582
CVE-2023-4839
CVE-2023-6697
WordPress WP Google Maps Plugin < 9.0.28 is vulnerable to Cross Site Scripting (XSS)
WP Google Maps <= 7.11.27 - Admin Settings CSRF
WP Google Maps <= 6.3.14 - Authenticated Stored Cross-Site Scripting (XSS) via CSRF
CVE-2022-47595
WP Google Maps <= 6.3.14 - Stored Cross-Site Scripting
WP Google Maps <= 7.11.27 - Cross-Site Request Forgery
WordPress Google Maps Plugin <= 2.3.9 - Cross Site Scripting
WordPress Google Maps Plugin <= 2 2.1.3 - Cross Site Scripting (XSS)
WordPress WP Google Maps plugin <= 7.10.41 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress WP Google Maps plugin <= 7.11.17 - Unauthenticated SQL Injection (SQLi) vulnerability
WordPress WP Google Maps plugin <= 7.11.27 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress WP Google Maps plugin <= 7.11.34 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2014-7182
WordPress WP Google Maps plugin <= 7.10.41 - Cross-Site Scripting (XSS) vulnerability
WP Go Maps (formerly WP Google Maps) <= 7.11.17 - SQL Injection
CVE-2019-14792
CVE-2021-24383
CVE-2021-36870