« Volver al listado

Weplugins

Weplugins WP Maps: vulnerabilidades y CVE

Weplugins WP Maps tiene 26 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE26
Últimos 12 meses12
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-13456Alta (7.5)0.75%—25 sept 2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8 via the 'page' parameter…
CVE-2026-13179Media (6.4)0.33%—25 sept 2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up to, and…
CVE-2026-66618Alta (7.6)0.38%—17 sept 2026
Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-18466Media (5.4)0.29%—19 ago 2026
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with a Subscriber account to create an unlimited number of options in the…
CVE-2026-16265Media (6.5)0.41%—7 ago 2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not restrict the operation it dispatches, allowing users with a Subscriber account to trigger…
CVE-2026-16263Alta (8.8)0.53%—7 ago 2026
The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not properly validate a user-controlled path before using it in a file inclusion, allowing users with a…
CVE-2026-39492Crítica (9.3)0.40%—15 jun 2026
Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
CVE-2026-9594Media (4.4)0.33%—6 jun 2026
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and…
CVE-2026-6381Alta (7.5)0.47%—18 may 2026
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to perform Local File Inclusion attacks.
CVE-2025-13364Media (6.4)0.27%—16 abr 2026
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and…
CVE-2026-2580Alta (7.5)0.51%—23 mar 2026
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including,…
CVE-2025-12062Alta (8.8)0.74%—17 feb 2026
The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template…
CVE-2025-3504Media (4.8)0.27%—1 may 2025
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the…
CVE-2025-3503Media (4.8)0.29%—1 may 2025
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the…
CVE-2025-3502Media (4.8)0.31%—1 may 2025
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the…
CVE-2024-2386Alta (8.8)0.46%—29 jun 2024
The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient…
CVE-2023-28172Alta (8.8)0.30%—12 nov 2023
Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
CVE-2023-23878Media (5.4)0.38%—4 abr 2023
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
CVE-2022-25600Alta (8.8)0.57%—11 mar 2022
Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
CVE-2021-24502Media (4.8)0.67%—9 ago 2021
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the…
CVE-2021-24130Alta (7.2)1.4%—18 mar 2021
Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
CVE-2015-9309Alta (8.8)0.70%—14 ago 2019
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
CVE-2015-9308Alta (8.8)0.70%—14 ago 2019
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
CVE-2015-9307Alta (8.8)0.70%—14 ago 2019
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
CVE-2016-10878Media (6.1)0.98%—12 ago 2019
The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
CVE-2015-9305Media (6.1)1.0%—12 ago 2019
The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1005 Data from Local System4
  3. T1190 Exploit Public-Facing Application3
  4. T1059 Command and Scripting Interpreter2
  5. T1059.007 JavaScript2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Weplugins