CVE Database /
CVE-2026-8386
CVE
CVE-2026-8386 — WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-8386
|
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10 |
Exposure of Sensitive Information to an Unauthorized Actor |
Unknown
|
< 10.0.10
|
10.0.10 |
2026-06-15 |
—
|
CVE-2026-8386
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings