Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | WP GO MapsAI | 2/9/2026 | 4/9/2026 | Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions. | |
| Aplazada | Baja (3.7) | 0.28% | — | WP GO MapsAI | 31/7/2026 | 26/8/2026 | The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Media (5.3) | 0.31% | — | WP GO MapsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. | |
| Aplazada | Media (5.3) | 0.38% | — | WP GO MapsAI | 19/6/2026 | 24/6/2026 | The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create arbitrary… | |
| Aplazada | Media (5.3) | 0.76% | — | WP GO MapsAI | 15/6/2026 | 23/7/2026 | The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields… | |
| Aplazada | Media (5.3) | 0.73% | — | WP GO MapsAI | 15/6/2026 | 23/7/2026 | The WP Go Maps WordPress plugin before 10.0.10 does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and… | |
| Aplazada | Media (6.4) | 0.26% | — | Wpgomaps WP GO MapsAI | 18/3/2026 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgmza_custom_js’ parameter in all versions up to, and including, 10.0.05 due to insufficient input sanitization and output escaping and missing capability check in the 'admin_post_wpgmza_save_settings'… | |
| Aplazada | Media (5.3) | 0.28% | — | WP GO MapsAI | 24/1/2026 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the processBackgroundAction() function in all versions up to, and including, 10.0.04. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Alta (8.8) | 1.8% | — | WP GO MapsAI | 11/11/2025 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped. | |
| Aplazada | Media (5.3) | 0.23% | — | WP GO MapsAI | 18/10/2025 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the… | |
| Aplazada | Media (5.4) | 0.19% | — | WP GO MapsAI | 9/10/2025 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including, 9.0.46. This is due to the plugin exposing state-changing REST actions through an AJAX bridge without proper CSRF token validation, and having destructive logic… | |
| Modificada | Alta (8.8) | 0.19% | — | Codecabin WP GO Maps | 27/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.40. | |
| Modificada | Media (5.4) | 0.37% | — | Codecabin WP GO Maps | 14/6/2024 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for authenticated attackers that have been explicitly granted permissions by an administrator, with contributor-level… | |
| Modificada | Media (5.4) | 0.32% | — | Codecabin WP GO Maps | 24/5/2024 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpgmza shortcode in all versions up to, and including, 9.0.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (6.5) | 0.80% | — | Codecabin WP GO Maps | 9/4/2024 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While… | |
| Modificada | Media (6.1) | 0.75% | — | Codecabin WP GO Maps | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29. | |
| Modificada | Media (5.4) | 0.32% | — | Codecabin WP GO Maps | 13/3/2024 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgmza' shortcode in all versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (4.8) | 0.34% | — | Codecabin WP GO Maps | 13/3/2024 | 17/6/2026 | The WP Go Maps for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 9.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web… | |
| Modificada | Media (6.1) | 1.0% | — | Wpgmaps WP GO Maps | 24/1/2024 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions up to, and including, 9.0.28 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (6.1) | 0.62% | — | Codecabin WP GO Maps | 8/1/2024 | 17/6/2026 | The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site. | |
| Modificada | Media (6.5) | 0.75% | — | Codecabin WP GO Maps | 14/3/2023 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions. | |
| Modificada | Media (5.4) | 0.56% | — | Codecabin WP GO Maps | 9/9/2021 | 17/6/2026 | Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title. | |
| Modificada | Media (5.4) | 0.58% | — | Codecabin WP GO Maps | 9/9/2021 | 17/6/2026 | Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address. | |
| Modificada | Media (5.4) | 2.5% | — | Codecabin WP GO Maps | 21/6/2021 | 17/6/2026 | The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 1.1% | — | Codecabin WP GO Maps | 9/8/2019 | 17/6/2026 | The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter. |