PLUGIN SECURITY

Is Wp Google Maps safe?

The easiest to use WordPress map plugin! Create a custom map, map block, store locator or map widget with high quality markers.

What this plugin does

  • Slug: wp-google-maps
  • Author: WPGMaps
  • 300000+ active installs
  • 96/100 rating (3032 reviews on wordpress.org)
  • 28313588 all-time downloads
  • On WordPress.org since 2012-01-26

Google Mapsleaflet mapmapmapsStore locator

Maintenance status

  • Latest known version: 10.1.06
  • Last updated: 2026-08-19 7:44am GMT
  • Tested up to WordPress: 7.1
  • Requires PHP: 7.0+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

26 known CVEs on file for Wp Google Maps.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15381 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.04 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Unknown < 10.1.04 10.1.04 2026-07-22 ✓ fixed in latest
CVE-2026-12238 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02 Missing Authorization Medium 5.3 < 10.1.02 10.1.02 2026-06-19 ✓ fixed in latest
CVE-2026-8386 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 10.0.10 10.0.10 2026-06-15 ✓ fixed in latest
CVE-2026-8385 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10 Exposure of Sensitive Information to an Unauthorized Actor Unknown < 10.0.10 10.0.10 2026-06-05 ✓ fixed in latest
CVE-2025-11307 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.48 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 8.8 < 9.0.48 9.0.48 2025-10-21 ✓ fixed in latest
CVE-2025-11703 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.49 Acceptance of Extraneous Untrusted Data With Trusted Data Medium 5.3 < 9.0.49 9.0.49 2025-10-17 ✓ fixed in latest
CVE-2025-11166 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47 Cross-Site Request Forgery (CSRF) Medium 5.4 < 9.0.47 9.0.47 2025-10-08 ✓ fixed in latest
CVE-2025-24742 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.41 Cross-Site Request Forgery (CSRF) Medium 4.3 < 9.0.41 9.0.41 2025-01-24 ✓ fixed in latest
+ 34 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39 Unknown < 9.0.39 9.0.39 2024-06-14 ✓ fixed in latest
CVE-2024-5994 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.39 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 9.0.39 9.0.39 2024-06-13 ✓ fixed in latest
CVE-2024-3557 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.37 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 9.0.37 9.0.37 2024-05-23 ✓ fixed in latest
CVE-2024-29931 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.30 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 9.0.30 9.0.30 2024-03-25 ✓ fixed in latest
CVE-2023-6777 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.35 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.5 < 9.0.35 9.0.35 2024-03-18 ✓ fixed in latest
CVE-2023-4839 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.33 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 9.0.33 9.0.33 2024-03-12 ✓ fixed in latest
CVE-2024-1582 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.33 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 9.0.33 9.0.33 2024-03-12 ✓ fixed in latest
CVE-2023-6697 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.29 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 9.0.29 9.0.29 2024-01-23 ✓ fixed in latest
CVE-2023-6627 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.28 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 9.0.28 9.0.28 2023-12-18 ✓ fixed in latest
CVE-2022-47595 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.16 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 4.9 < 9.0.16 9.0.16 2023-01-20 ✓ fixed in latest
CVE-2021-36870 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.5 < 8.1.13 8.1.13 2021-06-15 ✓ fixed in latest
CVE-2021-24383 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 8.1.12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 8.1.12 8.1.12 2021-06-07 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35 Unknown < 7.11.35 7.11.35 2019-07-10 ✓ fixed in latest
CVE-2019-14792 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.35 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 7.11.35 7.11.35 2019-07-08 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28 Unknown < 7.11.28 7.11.28 2019-06-16 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28 Unknown < 7.11.28 7.11.28 2019-06-03 ✓ fixed in latest
CVE-2019-10692 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.18 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 7.11.18 7.11.18 2019-04-02 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.18 Unknown < 7.11.18 7.11.18 2019-04-02 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.10.43 Unknown < 7.10.43 7.10.43 2019-03-12 ✓ fixed in latest
CVE-2019-9912 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.10.43 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 7.10.43 7.10.43 2019-02-05 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15 Unknown < 6.3.15 6.3.15 2016-11-10 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 2.1.4 Unknown < 2.1.4 2.1.4 2016-08-15 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 3.0.0 Unknown < 3.0.0 3.0.0 2015-08-20 ✓ fixed in latest
CVE-2014-7182 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.0.27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 6.0.27 6.0.27 2014-09-25 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.06 Unknown < 10.0.06 10.0.06 0000-00-00 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.05 Medium 5.3 < 10.0.05 10.0.05 0000-00-00 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.06 Unknown < 10.1.06 10.1.06 0000-00-00 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 6.3.15 Unknown < 6.3.15 6.3.15 ✓ fixed in latest
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 7.11.28 Unknown < 7.11.28 7.11.28 ✓ fixed in latest
WP Google Maps <= 6.3.14 - Authenticated Stored Cross-Site Scripting (XSS) via CSRF Unknown < 6.3.15 6.3.15 ✓ fixed in latest
WP Google Maps <= 7.11.27 - Admin Settings CSRF Unknown < 7.11.28 7.11.28 ✓ fixed in latest
CVE-2026-0593 WP Go Maps (formerly WP Google Maps) < 10.0.05 - Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification Unknown < 10.0.05 10.0.05 ✓ fixed in latest
CVE-2026-4268 WP Go Maps (formerly WP Google Maps) < 10.0.06 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via admin_post_wpgmza_save_settings Unknown < 10.0.06 10.0.06 ✓ fixed in latest
CVE-2026-25466 WP Go Maps – Google Map, OpenStreetMap, Leaflet Map < 10.1.06 - Missing Authorization Unknown < 10.1.06 10.1.06 ✓ fixed in latest

How to fix it

Keep Wp Google Maps updated — 10.1.06 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.