Weplugins develops WordPress mapping plugins with a recurring vulnerability profile centered on web application input handling, particularly cross-site scripting, cross-site request forgery, and SQL injection affecting its WP Maps product. These weakness classes reflect the typical risks present in plugins that accept user input and interact with databases in the WordPress ecosystem. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weplugins over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-9308HIGH The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. | Aug 14, 2019 | 8.8 | 28 | NO | NO |
CVE-2023-28172HIGH Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions. | Nov 12, 2023 | 8.8 | 24 | NO | NO |
CVE-2015-9309HIGH The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. | Aug 14, 2019 | 8.8 | 24 | NO | NO |
CVE-2015-9307HIGH The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. | Aug 14, 2019 | 8.8 | 24 | NO | NO |
CVE-2022-25600HIGH Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3). | Mar 11, 2022 | 8.8 | 22 | NO | NO |
CVE-2021-24130HIGH Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection throu | Mar 18, 2021 | 7.2 | 22 | NO | NO |
CVE-2016-10878MEDIUM The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. | Aug 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2023-23878MEDIUM Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions. | Apr 4, 2023 | 5.4 | 19 | NO | NO |
CVE-2021-24502MEDIUM The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high | Aug 9, 2021 | 4.8 | 18 | NO | NO |
CVE-2025-3503MEDIUM The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site | May 1, 2025 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weplugins.
Media articles that mention a CVE ID that affects a product developed by Weplugins — matched by CVE ID, not by vendor name.