← WordPress Vulnerabilities
WordPress security by component

WP Go Maps

WP Go Maps is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 6.4.

Plugin slug: wp-go-maps

CVE-2026-8386: WP Go Maps: A security weakness

WP Go Maps is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 10.0.10.

PublishedJun 15, 2026
Known safe version10.0.10
Safe version
Jun 15, 2026 CVE-2026-8386
WP Go Maps: A security weakness
WP Go Maps is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 10.0.10.
10.0.10
CVE5.3
NVDPending
Jun 15, 2026 CVE-2026-8385
WP Go Maps: A security weakness
WP Go Maps is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 10.0.10.
10.0.10
CVE5.3
NVDPending
Jan 27, 2025 CVE-2025-24742
WP Go Maps: Cross-site request forgery
WP Go Maps is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Apr 09, 2024 CVE-2023-6777
WP Go Maps (formerly WP Google Maps): A security weakness
WP Go Maps (formerly WP Google Maps) is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD6.5
Mar 13, 2024 CVE-2024-1582
WP Go Maps (formerly WP Google Maps): Cross-site scripting
WP Go Maps (formerly WP Google Maps) is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 13, 2024 CVE-2023-4839
Wp Go Maps: Cross-site scripting
Wp Go Maps is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jan 24, 2024 CVE-2023-6697
WP Go Maps (formerly WP Google Maps): Cross-site scripting
WP Go Maps (formerly WP Google Maps) is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Jan 08, 2024 CVE-2023-6627
WP Go Maps (formerly WP Google Maps): A security weakness
WP Go Maps (formerly WP Google Maps) is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.1
NVD6.1
Jun 21, 2021 CVE-2021-24383
WP Google Maps: Cross-site scripting
WP Google Maps is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Mar 22, 2019 CVE-2019-9912
Wp Go Maps: Cross-site scripting
Wp Go Maps is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1