Weplugins
Weplugins WP Maps: vulnerabilidades y CVE
Weplugins WP Maps tiene 26 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses12
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13456 | Alta (7.5) | 0.75% | — | 25 sept 2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter… |
| CVE-2026-13179 | Media (6.4) | 0.33% | — | 25 sept 2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and… |
| CVE-2026-66618 | Alta (7.6) | 0.38% | — | 17 sept 2026 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. |
| CVE-2026-18466 | Media (5.4) | 0.29% | — | 19 ago 2026 | The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the… |
| CVE-2026-16265 | Media (6.5) | 0.41% | — | 7 ago 2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger… |
| CVE-2026-16263 | Alta (8.8) | 0.53% | — | 7 ago 2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a… |
| CVE-2026-39492 | Crítica (9.3) | 0.40% | — | 15 jun 2026 | Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions. |
| CVE-2026-9594 | Media (4.4) | 0.33% | — | 6 jun 2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and… |
| CVE-2026-6381 | Alta (7.5) | 0.47% | — | 18 may 2026 | The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks. |
| CVE-2025-13364 | Media (6.4) | 0.27% | — | 16 abr 2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and… |
| CVE-2026-2580 | Alta (7.5) | 0.51% | — | 23 mar 2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including,… |
| CVE-2025-12062 | Alta (8.8) | 0.74% | — | 17 feb 2026 | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template… |
| CVE-2025-3504 | Media (4.8) | 0.27% | — | 1 may 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-3503 | Media (4.8) | 0.29% | — | 1 may 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-3502 | Media (4.8) | 0.31% | — | 1 may 2025 | The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2024-2386 | Alta (8.8) | 0.46% | — | 29 jun 2024 | The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient… |
| CVE-2023-28172 | Alta (8.8) | 0.30% | — | 12 nov 2023 | Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions. |
| CVE-2023-23878 | Media (5.4) | 0.38% | — | 4 abr 2023 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions. |
| CVE-2022-25600 | Alta (8.8) | 0.57% | — | 11 mar 2022 | Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3). |
| CVE-2021-24502 | Media (4.8) | 0.67% | — | 9 ago 2021 | The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the… |
| CVE-2021-24130 | Alta (7.2) | 1.4% | — | 18 mar 2021 | Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+). |
| CVE-2015-9309 | Alta (8.8) | 0.70% | — | 14 ago 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. |
| CVE-2015-9308 | Alta (8.8) | 0.70% | — | 14 ago 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature. |
| CVE-2015-9307 | Alta (8.8) | 0.70% | — | 14 ago 2019 | The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature. |
| CVE-2016-10878 | Media (6.1) | 0.98% | — | 12 ago 2019 | The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. |
| CVE-2015-9305 | Media (6.1) | 1.0% | — | 12 ago 2019 | The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.