CVE Database /
CVE-2026-12238
CVE · Medium
CVE-2026-12238 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12238
|
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02 |
Missing Authorization |
Medium
5.3
|
< 10.1.02
|
10.1.02 |
2026-06-19 |
—
|
CVE-2026-12238
A security flaw exists in WP Go Maps – Most Popular Map Plugin for WordPress, affecting all versions up to 10.1.01. The issue arises from inadequate verification of user authorization, allowing unauthorized users to create arbitrary records in specific database tables controlled by the plugin. This vulnerability is exploitable through a parameter named phpClass, which can be manipulated to bypass namespace validation and insert unwanted data into relevant tables.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings