← Back

Weplugins

weplugins

13 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Wp Maps
wp_maps

CVEs (13)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Weplugins
1Wp Maps
Jun 17, 2026
May 1, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter...Show more
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Weplugins
1Wp Maps
Jun 17, 2026
May 1, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter...Show more
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Weplugins
1Wp Maps
Jun 17, 2026
May 1, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilter...Show more
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Weplugins
1Wp Maps
Jun 17, 2026
Nov 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
1Weplugins
1Wp Maps
Jun 17, 2026
Apr 4, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
2Fedoraproject
Weplugins
2Fedora
Wp Maps
Jun 17, 2026
Mar 11, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
1Weplugins
1Wp Maps
Jun 17, 2026
Aug 9, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltere...Show more
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowedShow less
1Weplugins
1Wp Maps
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
1Weplugins
1Wp Maps
May 7, 2025
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
1Weplugins
1Wp Maps
May 7, 2025
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
1Weplugins
1Wp Maps
May 7, 2025
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
1Weplugins
1Wp Maps
May 7, 2025
Aug 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
1Weplugins
1Wp Maps
May 7, 2025
Aug 12, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.