Codecabin develops WordPress plugins spanning mapping, testimonial display, and pricing-table functionality—a narrow product portfolio that sits within widely deployed WordPress installations. The vulnerability profile concentrates around common web-application weaknesses including cross-site scripting, CSRF, SQL injection, and path traversal, reflecting the input-handling and access-control demands of WordPress plugin development, and has tended to attract public exploit availability. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codecabin over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10692CRITICAL In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement. | Apr 2, 2019 | 9.8 | 87 | NO | YES |
CVE-2019-9912MEDIUM The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO. | Mar 22, 2019 | 6.1 | 29 | NO | YES |
CVE-2021-24383MEDIUM The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated | Jun 21, 2021 | 5.4 | 28 | NO | YES |
CVE-2024-13628MEDIUM The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which | Feb 26, 2025 | 6.1 | 27 | NO | YES |
CVE-2024-29931MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a thro | Mar 27, 2024 | 6.1 | 27 | NO | YES |
CVE-2025-24742HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.40. | Jan 27, 2025 | 8.8 | 25 | NO | NO |
CVE-2022-47595MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions. | Mar 14, 2023 | 6.5 | 22 | NO | NO |
CVE-2019-14792MEDIUM The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter. | Aug 9, 2019 | 5.4 | 20 | NO | NO |
CVE-2021-36871MEDIUM Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_ma | Sep 9, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-36870MEDIUM Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_ | Sep 9, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codecabin.
Media articles that mention a CVE ID that affects a product developed by Codecabin — matched by CVE ID, not by vendor name.