Wpgooglemap's vulnerability profile centers on its WordPress plugin for embedding Google Maps, where disclosures cluster around web-application input handling and access control. The recurrent weakness classes—cross-site request forgery, cross-site scripting, and missing authorization—are typical of WordPress plugins that bridge user input with third-party map services. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpgooglemap over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25081MEDIUM The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins dele | Feb 28, 2022 | 6.5 | 22 | NO | NO |
CVE-2021-25011MEDIUM The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper authorisation and CSRF in most of its AJAX actions, which could allow any authenticated use | Feb 28, 2022 | 5.7 | 21 | NO | NO |
CVE-2024-13306MEDIUM The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as adm | Feb 15, 2025 | 4.3 | 15 | NO | NO |
CVE-2024-13208MEDIUM The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its settings, which could allow high privilege users such as adm | Feb 15, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpgooglemap.
Media articles that mention a CVE ID that affects a product developed by Wpgooglemap — matched by CVE ID, not by vendor name.