CVE · Medium

CVE-2023-6777 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.35

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6777 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.35 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 9.0.35 9.0.35 2024-03-18

CVE-2023-6777

The WP Go Maps plugin for WordPress through version 9.0.34 allows unauthenticated attackers to retrieve the Google API key because the plugin stores it in publicly accessible files. An attacker without authentication can obtain this key and use it to make API requests, potentially exhausting the quota and rendering the plugin's map features unusable, though this vulnerability does not directly compromise site security.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.