WEPLUGINS WP Maps 2.3.9 Lite Edition for WordPress

CPE Details

WEPLUGINS WP Maps 2.3.9 Lite Edition for WordPress
2.3.9
2025-05-07
11h35 +00:00
2025-05-07
11h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:weplugins:wp_maps:2.3.9:*:*:*:lite:wordpress:*:*

Informations

Vendor

weplugins

Product

wp_maps

Version

2.3.9

Software Edition

lite

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-3504 2025-05-01 06h00 +00:00 The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
4.8
Medium
CVE-2025-3503 2025-05-01 06h00 +00:00 The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
4.8
Medium
CVE-2025-3502 2025-05-01 06h00 +00:00 The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
4.8
Medium
CVE-2023-28172 2023-11-12 22h24 +00:00 Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
8.8
High
CVE-2023-23878 2023-04-04 11h38 +00:00 Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
5.9
Medium
CVE-2022-25600 2022-03-11 17h54 +00:00 Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
8.8
High
CVE-2021-24130 2021-03-18 13h57 +00:00 Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
7.2
High
CVE-2015-9307 2019-08-14 13h24 +00:00 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
8.8
High
CVE-2015-9308 2019-08-14 13h23 +00:00 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
8.8
High
CVE-2015-9309 2019-08-14 13h22 +00:00 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
8.8
High
CVE-2016-10878 2019-08-12 12h52 +00:00 The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
6.1
Medium