CVE · Medium

CVE-2025-11703 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.49

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-11703 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.49 Acceptance of Extraneous Untrusted Data With Trusted Data Medium 5.3 < 9.0.49 9.0.49 2025-10-17

CVE-2025-11703

The WP Go Maps plugin for WordPress has a security flaw in versions up to 9.0.48, where it doesn't properly validate data coming from users before using it to populate cached responses. As a result, malicious input can be injected into the cache, allowing attackers to manipulate search results without needing authentication. This vulnerability affects all versions of the plugin prior to 9.0.48.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.