CVE Database /
CVE-2026-8385
CVE
CVE-2026-8385 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-8385
|
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10 |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 10.0.10
|
10.0.10 |
2026-06-05 |
—
|
CVE-2026-8385
The WP Go Maps plugin for WordPress contains a flaw in its handling of unauthorized access to sensitive data through an AJAX fallback route. This vulnerability affects all versions up to and including 10.0.09, allowing unauthenticated attackers to retrieve marker records that are not publicly visible, including their titles, categories, addresses, and descriptions.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings