CVE · Medium

CVE-2025-11166 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11166 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47 Cross-Site Request Forgery (CSRF) Medium 5.4 < 9.0.47 9.0.47 2025-10-08

CVE-2025-11166

The WP Go Maps plugin for WordPress has a security flaw that lets hackers trick administrators into making changes they didn't intend. This happens because the plugin doesn't check for a special code when it receives certain types of requests, allowing anyone to create, edit or delete map features without needing permission. As a result, attackers can use this weakness to make unauthorized changes to maps, even deleting multiple markers at once.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.