WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro Wp Google Maps?

Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Wp Google Maps — verificado contra la base de datos de seguridad local de WP Clinic.

Qué hace este plugin

  • Slug: wp-google-maps
  • 300000+ instalaciones activas

Google Mapsleaflet mapmapmapsStore locator

Estado de mantenimiento

  • Última versión conocida: 10.1.04
  • Requiere PHP: 7.0+
  • PHP máximo soportado (analizado): 8.4

Vulnerabilidades conocidas

24 CVEs conocidos registrados para Wp Google Maps.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-12238 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02 Falta de control de autorización Media 5,3 < 10.1.02 10.1.02 2026-06-19 ✓ corregido en la última versión
CVE-2026-8386 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10 Exposición de información sensible a un actor no autorizado Desconocido < 10.0.10 10.0.10 2026-06-15 ✓ corregido en la última versión
CVE-2026-8385 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10 Exposición de información sensible a un actor no autorizado Desconocido < 10.0.10 10.0.10 2026-06-05 ✓ corregido en la última versión
CVE-2025-11307 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.48 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 8,8 < 9.0.48 9.0.48 2025-10-21 ✓ corregido en la última versión
CVE-2025-11703 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.49 Aceptación de datos no confiables adicionales junto con datos confiables Media 5,3 < 9.0.49 9.0.49 2025-10-17 ✓ corregido en la última versión
CVE-2025-11166 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47 Falsificación de petición en sitios cruzados (CSRF) Media 5,4 < 9.0.47 9.0.47 2025-10-08 ✓ corregido en la última versión
CVE-2025-24742 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.41 Falsificación de petición en sitios cruzados (CSRF) Media 4,3 < 9.0.41 9.0.41 2025-01-24 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39 Desconocido < 9.0.39 9.0.39 2024-06-14 ✓ corregido en la última versión

CVE-2026-12238

The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary records in plugin database tables (maps, markers, circles, polygons, polylines, rectangles, and point labels) by supplying a WPGMZA-namespaced CRUD-backed class name via the phpClass parameter. The namespace validation check (requiring the 'WPGMZA' prefix) does not prevent exploitation because classes such as WPGMZA\Map and WPGMZA\Marker satisfy it while still triggering an INSERT into the corresponding plugin table before the route rejects the request.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-8386

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2026-8385

The WP Go Maps plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 10.0.09 via the datatables AJAX fallback route. This makes it possible for unauthenticated attackers to extract marker records that the site owner has not approved for public display, including their title, category, address and description fields.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-11307

The Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.47 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-11703

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-11166

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic reachable via GET requests with no permission_callback. This makes it possible for unauthenticated attackers to force logged-in administrators to create, update, or delete markers and geometry features via CSRF attacks, and allows anonymous users to trigger mass deletion of markers via unsafe GET requests.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2025-24742

The WP Go Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9.0.40. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39

<p>WordPress WP Google Maps Plugin <= 9.0.38 is vulnerable to Cross Site Scripting (XSS)</p><p>Software: WP Google Maps</p><p>Link: https://wordpress.org/plugins/wp-google-maps/#developers</p><p>Affected Version <= 9.0.38</p><p>Fixed in version 9.0.39 </p>

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

+ 27 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2024-5994 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 9.0.39 9.0.39 2024-06-13 ✓ corregido en la última versión
CVE-2024-3557 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.37 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 9.0.37 9.0.37 2024-05-23 ✓ corregido en la última versión
CVE-2024-29931 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.30 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 9.0.30 9.0.30 2024-03-25 ✓ corregido en la última versión
CVE-2023-6777 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.35 Exposición de información sensible a un actor no autorizado Media 6,5 < 9.0.35 9.0.35 2024-03-18 ✓ corregido en la última versión
CVE-2023-4839 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.33 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 4,8 < 9.0.33 9.0.33 2024-03-12 ✓ corregido en la última versión
CVE-2024-1582 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.33 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 9.0.33 9.0.33 2024-03-12 ✓ corregido en la última versión
CVE-2023-6697 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.29 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 9.0.29 9.0.29 2024-01-23 ✓ corregido en la última versión
CVE-2023-6627 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.28 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 9.0.28 9.0.28 2023-12-18 ✓ corregido en la última versión
CVE-2022-47595 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.16 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 4,9 < 9.0.16 9.0.16 2023-01-20 ✓ corregido en la última versión
CVE-2021-36870 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.13 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,5 < 8.1.13 8.1.13 2021-06-15 ✓ corregido en la última versión
CVE-2021-24383 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.12 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 8.1.12 8.1.12 2021-06-07 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35 Desconocido < 7.11.35 7.11.35 2019-07-10 ✓ corregido en la última versión
CVE-2019-14792 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 5,4 < 7.11.35 7.11.35 2019-07-08 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28 Desconocido < 7.11.28 7.11.28 2019-06-16 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28 Desconocido < 7.11.28 7.11.28 2019-06-03 ✓ corregido en la última versión
CVE-2019-10692 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.18 Neutralización incorrecta de elementos especiales en un comando SQL (inyección SQL) Crítica 9,8 < 7.11.18 7.11.18 2019-04-02 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.18 Desconocido < 7.11.18 7.11.18 2019-04-02 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.10.43 Desconocido < 7.10.43 7.10.43 2019-03-12 ✓ corregido en la última versión
CVE-2019-9912 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.10.43 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 7.10.43 7.10.43 2019-02-05 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15 Desconocido < 6.3.15 6.3.15 2016-11-10 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 2.1.4 Desconocido < 2.1.4 2.1.4 2016-08-15 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 3.0.0 Desconocido < 3.0.0 3.0.0 2015-08-20 ✓ corregido en la última versión
CVE-2014-7182 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.0.27 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Desconocido < 6.0.27 6.0.27 2014-09-25 ✓ corregido en la última versión
CVE-2026-4268 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.06 Desconocido < 10.0.06 10.0.06 0000-00-00 ✓ corregido en la última versión
CVE-2026-0593 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.05 Media 5,3 < 10.0.05 10.0.05 0000-00-00 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15 Desconocido < 6.3.15 6.3.15 ✓ corregido en la última versión
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28 Desconocido < 7.11.28 7.11.28 ✓ corregido en la última versión

CVE-2024-5994

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Version 9.0.39 adds a caution to make administrators aware of the possibility for abuse if permissions are granted to lower-level users.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-3557

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-29931

Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.30). Rafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.0.30. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6777

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered by the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2023-4839

Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.33). Marco Wotschka - Wordfence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.0.33. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2024-1582

Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.33). Richard Telleng (stueotue) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.0.33. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6697

Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.29). Nex Team discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.0.29. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2023-6627

Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.28). Marc Montpas discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.0.28. Have additional information or questions about this entry? Get in touch.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2022-47595

Update the WordPress WP Google Maps plugin to the latest available version (at least 9.0.16). rezaduty discovered and reported this Directory Traversal vulnerability in WordPress WP Google Maps Plugin. This could allow a malicious actor to see all files in a given directory or determine if certain files/directories exist in given folder. This can be used to exploit other weaknesses in the system This vulnerability has been fixed in version 9.0.16.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-36870

Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities discovered by Vlad Visse (Patchstack Red Team) in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2021-24383

The plugin did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue Note: The vendor attributed the issue in the changelog to the wrong reporter (us, WPScan, as we reported it on behalf of the reporter). This will be corrected in the next version

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35

Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WP Google Maps plugin (versions <= 7.11.34).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-14792

Lack of CSRF and authorisation checks, as well as sanitisation in the wpgmaps_head() function in legacy-core.php can lead to stored XSS issues

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28

Cross-Site Request Forgery (CSRF) vulnerability found in WordPress WP Google Maps plugin (versions <= 7.11.27).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28

The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.11.27. This is due to missing nonce validation on the wpgmza_settings_page_post() function. This makes it possible for authenticated attackers to modify the plugin's settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2019-10692

In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.18

Unauthenticated SQL Injection (SQLi) vulnerability found by Thomas Chauchefoin in WordPress WP Google Maps plugin (versions <= 7.11.17).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.10.43

Reflected Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Google Maps plugin (versions <= 7.10.41).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2019-9912

Cross-Site Scripting (XSS) vulnerability found by Tim Coen in WordPress WP Google Maps plugin (versions <= 7.10.41).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15

The WP Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_store_locator_query_string’ parameter in versions up to, and including, 6.3.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 2.1.4

Because of this vulnerability, the attackers can steal users' session tokens, or perform arbitrary actions on their behalf. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 3.0.0

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2014-7182

The WP Google Maps plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 6.0.26 via the 'poly_id' parameter (in the edit_poly, edit_polyline, or edit_marker actions) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-4268

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings' hook anonymous function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2026-0593

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global map engine settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: euvd.enisa.europa.eu

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15

The WP Google Maps WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) via CSRF security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28

The WP Google Maps WordPress plugin was affected by an Admin Settings CSRF security vulnerability.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Mantén Wp Google Maps actualizado — 10.1.04 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.