Wp Go Maps
Vendor:
First CVE: Oct 22, 2014 · Active for 11 years
16
Total CVEs
More Total CVEs than 92% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wp Go Maps over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 22, 2014
11 years ago
Most Recent CVE
Jan 27, 2025
543 days ago
CVE Severity & Scoring
Wp Go Maps16 CVEs
88%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (93.8%)
Unknown1 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (93.8%)
High0 (0.0%)
Unknown1 (6.3%)
User Interaction
None3 (18.8%)
Unknown1 (6.3%)
Required12 (75.0%)
Privileges Required
Low8 (50.0%)
High1 (6.3%)
None6 (37.5%)
Unknown1 (6.3%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10692CRITICAL In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement. | Apr 2, 2019 | 9.8 | 87 | NO | YES |
CVE-2019-9912MEDIUM The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO. | Mar 22, 2019 | 6.1 | 29 | NO | YES |
CVE-2021-24383MEDIUM The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated | Jun 21, 2021 | 5.4 | 28 | NO | YES |
CVE-2024-29931MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a thro | Mar 27, 2024 | 6.1 | 27 | NO | YES |
CVE-2025-24742HIGH Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.40. | Jan 27, 2025 | 8.8 | 25 | NO | NO |
CVE-2022-47595MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions. | Mar 14, 2023 | 6.5 | 22 | NO | NO |
CVE-2019-14792MEDIUM The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter. | Aug 9, 2019 | 5.4 | 20 | NO | NO |
CVE-2021-36871MEDIUM Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_ma | Sep 9, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-36870MEDIUM Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_ | Sep 9, 2021 | 5.4 | 19 | NO | NO |
CVE-2023-6627MEDIUM The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Jav | Jan 8, 2024 | 6.1 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.2% of CVEs· 97th percentile
Nuclei
3 CVEs
18.8% of CVEs· 98th percentile
ExploitDB
1 CVE
6.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Wp Go Maps
Top CWEs
Versions
No cataloged versions.