Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2023-6627

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.
Attacker Value
Unknown

CVE-2022-47595

Disclosure Date: March 14, 2023 (last updated November 08, 2023)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP Google Maps) plugin <= 9.0.15 versions.
Attacker Value
Unknown

CVE-2021-36871

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.
Attacker Value
Unknown

CVE-2021-36870

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps plugin (versions <= 8.1.12). Vulnerable parameters: &dataset_name, &wpgmza_gdpr_retention_purpose, &wpgmza_gdpr_company_name, &name #2, &name, &polyname #2, &polyname, &address.
Attacker Value
Unknown

CVE-2021-24383

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2019-14792

Disclosure Date: August 09, 2019 (last updated November 27, 2024)
The WP Google Maps plugin before 7.11.35 for WordPress allows XSS via the wp-admin/ rectangle_name or rectangle_opacity parameter.
0
Attacker Value
Unknown

CVE-2019-9912

Disclosure Date: March 22, 2019 (last updated November 27, 2024)
The wp-google-maps plugin before 7.10.43 for WordPress has XSS via the wp-admin/admin.php PATH_INFO.
Attacker Value
Unknown

CVE-2014-7182

Disclosure Date: October 22, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.
0