CVE · Medium

CVE-2019-14792 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-14792 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 7.11.35 7.11.35 2019-07-08

CVE-2019-14792

The WP Go Maps plugin before version 7.11.35 contains multiple security flaws in the wpgmaps_head() function within legacy-core.php, including missing CSRF protections, absent authorization validation, and insufficient input sanitization that enable attackers to inject and store malicious scripts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.