CVE

CVE-2026-15381 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.04

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15381 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.04 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 10.1.04 10.1.04 2026-07-22

CVE-2026-15381

A vulnerability exists in the WP Go Maps plugin for WordPress prior to version 10.1.04, where an unsanitized parameter is incorporated into a database query without proper protection, enabling malicious actors to inject arbitrary SQL code. This weakness permits unauthorized individuals to execute potentially destructive SQL commands.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.