CVE Database /
CVE-2025-11166
CVE · Medium
CVE-2025-11166 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-11166
|
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 9.0.47
|
9.0.47 |
2025-10-08 |
—
|
CVE-2025-11166
The WP Go Maps plugin for WordPress has a security flaw that lets hackers trick administrators into making changes they didn't intend. This happens because the plugin doesn't check for a special code when it receives certain types of requests, allowing anyone to create, edit or delete map features without needing permission. As a result, attackers can use this weakness to make unauthorized changes to maps, even deleting multiple markers at once.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings