CVE · Medium

CVE-2026-12238 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12238 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02 Missing Authorization Medium 5.3 < 10.1.02 10.1.02 2026-06-19

CVE-2026-12238

A security flaw exists in WP Go Maps – Most Popular Map Plugin for WordPress, affecting all versions up to 10.1.01. The issue arises from inadequate verification of user authorization, allowing unauthorized users to create arbitrary records in specific database tables controlled by the plugin. This vulnerability is exploitable through a parameter named phpClass, which can be manipulated to bypass namespace validation and insert unwanted data into relevant tables.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.