Plugin Vulnerability Hub
Plugin 24 known issues Latest disclosed Jun 05, 2026

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters Vulnerabilities

Review known vulnerability records for the WordPress plugin WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters (`wp-google-map-plugin`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-9594, CVE-2025-13364 and CVE-2026-39492, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
24
High or Critical
11
Patch Coverage
100%
Last Updated
Jun 05, 2026
Related Security Guides

Use these guides while reviewing WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
19
1. Match the Package
Confirm the installed WordPress plugin slug is wp-google-map-plugin before acting on any CVE from this cluster.
2. Sort by Severity
Start with 11 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
24 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
21
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2025-12062
WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion
Local File Inclusion Versions up to 4.8.6 4.8.7 CVSS 8.8
CVE-2024-2386
WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) S...
SQL Injection Versions up to 4.6.1 4.6.2 CVSS 8.8
CVE-2015-9309
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions before 2.3.10 2.3.10 CVSS 8.8
CVE-2015-9307
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions before 2.3.10 2.3.10 CVSS 8.8
CVE-2015-9308
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions before 2.3.10 2.3.10 CVSS 8.8
CVE-2026-39492
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters...
SQL Injection Versions up to 4.9.1 4.9.2 CVSS 7.5
CVE-2026-2580
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters...
SQL Injection Versions up to 4.9.1 4.9.2 CVSS 7.5
CVE-2026-3222
WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter
SQL Injection Versions up to 4.9.1 4.9.2 CVSS 7.5
CVE-2025-12062 High 4.8.7
CVE-2025-12062 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters Local File Inclusion

WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion

CVE-2024-2386 High 4.6.2
CVE-2024-2386 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters SQL Injection

WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection

CVE-2015-9309 High 2.3.10
CVE-2015-9309 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters Cross-Site Request Forgery

WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery

CVE-2015-9307 High 2.3.10
CVE-2015-9307 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters Cross-Site Request Forgery

WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery

CVE-2015-9308 High 2.3.10
CVE-2015-9308 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters Cross-Site Request Forgery

WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery

CVE-2026-39492 High 4.9.2
CVE-2026-39492 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters SQL Injection

WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection

CVE-2026-2580 High 4.9.2
CVE-2026-2580 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters SQL Injection

WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter

CVE-2026-3222 High 4.9.2
CVE-2026-3222 WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters SQL Injection

WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
24 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 11 high severity findings.
Recent CVEs
CVE-2026-9594, CVE-2025-13364 and CVE-2026-39492
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

CVE-2025-13364 Medium Patch path listed

CVE-2025-13364: WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all...

Published
Apr 15, 2026
Patch Status
4.8.8
Known Vulnerabilities

Reports for WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-9594
CVE-2026-9594: WP Maps <= 4.9.4 - Authenticated (Admin+) Stored Cross-Site Scripting via 'location_messages' Parameter

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and...

Published
Jun 05, 2026
Patched Release
4.9.5
Affected Versions
Versions up to 4.9.4
Next Step
Update to 4.9.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13364
CVE-2025-13364: WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and...

Published
Apr 15, 2026
Patched Release
4.8.8
Affected Versions
Versions up to 4.8.7
Next Step
Update to 4.8.8 or newer if supported.
Plugin High Patched: Yes CVE-2026-39492
CVE-2026-39492: WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...

Published
Apr 08, 2026
Patched Release
4.9.2
Affected Versions
Versions up to 4.9.1
Next Step
Update to 4.9.2 or newer if supported.
Plugin High Patched: Yes CVE-2026-2580
CVE-2026-2580: WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.9.1 - Unauthenticated SQL Injection via 'orderby' Parameter

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parame...

Published
Mar 22, 2026
Patched Release
4.9.2
Affected Versions
Versions up to 4.9.1
Next Step
Update to 4.9.2 or newer if supported.
Plugin High Patched: Yes CVE-2026-3222
CVE-2026-3222: WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter

The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all versions up to, and including, 4.9.1. This is due to the plugin's database abstraction layer (`FlipperCode_Model_Base::is_column()`) treating user input wrapped...

Published
Mar 10, 2026
Patched Release
4.9.2
Affected Versions
Versions up to 4.9.1
Next Step
Update to 4.9.2 or newer if supported.
Plugin High Patched: Yes CVE-2025-12062
CVE-2025-12062: WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the fc_load_template function. This makes it possible for authenticated attackers, w...

Published
Feb 16, 2026
Patched Release
4.8.7
Affected Versions
Versions up to 4.8.6
Next Step
Update to 4.8.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-67535
CVE-2025-67535: Maps <= 4.8.6 - Authenticated (Administrator+) PHP Object Injection

The Maps plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP...

Published
Nov 02, 2025
Patched Release
4.8.7
Affected Versions
Versions up to 4.8.6
Next Step
Update to 4.8.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3502
CVE-2025-3502: WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

Published
Apr 10, 2025
Patched Release
4.7.2
Affected Versions
Versions up to 4.7.1
Next Step
Update to 4.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3503
CVE-2025-3503: WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

Published
Apr 10, 2025
Patched Release
4.7.2
Affected Versions
Versions up to 4.7.1
Next Step
Update to 4.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3504
CVE-2025-3504: WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The WP Maps – Display Google Maps Perfectly with Ease plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authentica...

Published
Apr 10, 2025
Patched Release
4.7.2
Affected Versions
Versions up to 4.7.1
Next Step
Update to 4.7.2 or newer if supported.
Plugin High Patched: Yes CVE-2024-2386
CVE-2024-2386: WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection

The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode in all versions up to, and including, 4.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient pre...

Published
Jun 28, 2024
Patched Release
4.6.2
Affected Versions
Versions up to 4.6.1
Next Step
Update to 4.6.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-28172
CVE-2023-28172: WP Google Map Plugin <= 4.4.2 - Cross-Site Request Forgery via delete()

The WP Google Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4.2. This is due to missing or incorrect nonce validation on the delete() function of the WPGMP_Model_Group_Map, WPGMP_Model_Location, and WPGMP_Model_Map...

Published
Mar 13, 2023
Patched Release
4.4.3
Affected Versions
Versions up to 4.4.2
Next Step
Update to 4.4.3 or newer if supported.