PLUGIN SECURITY

Is Wp Google Map Plugin safe?

WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.

What this plugin does

  • Slug: wp-google-map-plugin
  • Author: Flipper Code - WordPress Development Company
  • 60000+ active installs
  • 86/100 rating (122 reviews on wordpress.org)
  • 3747102 all-time downloads
  • On WordPress.org since 2013-03-15

Google Mapsmap pluginopenstreetmapStore locatorwp google map

Maintenance status

  • Latest known version: 4.9.7
  • Last updated: 2026-08-14 7:10am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 5.3+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

26 known CVEs on file for Wp Google Map Plugin.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18466 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.8 Improper Access Control Unknown < 4.9.8 4.9.8 2026-08-19 ⚠ update needed
CVE-2026-16265 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.7 Uncontrolled Resource Consumption Unknown < 4.9.7 4.9.7 2026-08-07 ✓ fixed in latest
CVE-2026-16263 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 4.9.7 4.9.7 2026-08-03 ✓ fixed in latest
CVE-2026-28144 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.7 Insertion of Sensitive Information Into Sent Data Medium 4.3 < 4.9.7 4.9.7 2026-07-31 ✓ fixed in latest
CVE-2026-9594 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.4 < 4.9.5 4.9.5 2026-06-05 ✓ fixed in latest
CVE-2026-6381 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.3 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Unknown < 4.9.3 4.9.3 2026-05-18 ✓ fixed in latest
CVE-2025-13364 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.8.8 4.8.8 2026-04-15 ✓ fixed in latest
CVE-2026-39492 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.3 < 4.9.2 4.9.2 2026-04-08 ✓ fixed in latest
+ 29 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-12062 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.8 < 4.8.7 4.8.7 2026-02-16 ✓ fixed in latest
CVE-2025-67535 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7 Deserialization of Untrusted Data Medium 6.6 < 4.8.7 4.8.7 2025-11-02 ✓ fixed in latest
CVE-2024-2386 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.6.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 4.6.2 4.6.2 2024-06-28 ✓ fixed in latest
CVE-2023-28172 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3 Cross-Site Request Forgery (CSRF) Medium 5.4 < 4.4.3 4.4.3 2023-03-13 ✓ fixed in latest
CVE-2023-23878 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 4.4.0 4.4.0 2023-01-20 ✓ fixed in latest
CVE-2022-25600 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.4.3 Cross-Site Request Forgery (CSRF) High 8.8 < 4.4.3 4.4.3 2022-02-22 ✓ fixed in latest
CVE-2021-24130 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 4.1.5 4.1.5 2020-11-25 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.4 Unknown < 4.1.4 4.1.4 2020-11-25 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.0 Unknown < 4.1.0 4.1.0 2019-09-21 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.0 Unknown < 4.1.0 4.1.0 2019-09-21 ✓ fixed in latest
CVE-2018-0577 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.0.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.0.4 4.0.4 2018-04-27 ✓ fixed in latest
CVE-2016-10878 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 3.1.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.1.2 3.1.2 2016-07-27 ✓ fixed in latest
CVE-2015-9309 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.10 Cross-Site Request Forgery (CSRF) High 8.8 < 2.3.10 2.3.10 2015-08-21 ✓ fixed in latest
CVE-2015-9307, CVE-2015-9308, CVE-2015-9309 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.10 Cross-Site Request Forgery (CSRF) High 8.8 < 2.3.10 2.3.10 2015-08-21 ✓ fixed in latest
CVE-2015-9308 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.10 Cross-Site Request Forgery (CSRF) High 8.8 < 2.3.10 2.3.10 2015-08-21 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 3.0.0 Unknown < 3.0.0 3.0.0 2015-08-20 ✓ fixed in latest
CVE-2015-9305 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 2.3.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.3.7 2.3.7 2015-04-24 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.7.2 4.7.2 0000-00-00 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.2 Unknown < 4.9.2 4.9.2 0000-00-00 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.2 Unknown < 4.9.2 4.9.2 0000-00-00 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.1.0 Unknown < 4.1.0 4.1.0 ✓ fixed in latest
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 3.0.0 Unknown < 3.0.0 3.0.0 ✓ fixed in latest
WP Google Map Plugin < 3.0.0 - CSRF to Authenticated Cross-Site Scripting (XSS) Unknown < 3.0.0 3.0.0 ✓ fixed in latest
WP Google Map Plugin < 4.1.0 - CSRF to Unauthenticated PHP Object Injection Unknown < 4.1.0 4.1.0 ✓ fixed in latest
CVE-2025-3502 WP Maps < 4.7.2 - Admin+ Stored XSS Unknown < 4.7.2 4.7.2 ✓ fixed in latest
CVE-2025-3503 WP Maps < 4.7.2 - Admin+ Stored XSS Unknown < 4.7.2 4.7.2 ✓ fixed in latest
CVE-2025-3504 WP Maps < 4.7.2 - Admin+ Stored XSS Unknown < 4.7.2 4.7.2 ✓ fixed in latest
CVE-2026-3222 WP Maps < 4.9.2 - Unauthenticated SQL Injection via 'location_id' Parameter Unknown < 4.9.2 4.9.2 ✓ fixed in latest
CVE-2026-2580 WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters < 4.9.2 - Unauthenticated SQL Injection via 'orderby' Parameter Unknown < 4.9.2 4.9.2 ✓ fixed in latest

How to fix it

Keep Wp Google Map Plugin updated — 4.9.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.