PT-2025-46300 · WordPress · Wp Go Maps+1
Sunghoon Kim
·
Published
2025-11-11
·
Updated
2025-12-04
·
CVE-2025-11307
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WP Go Maps (formerly WP Google Maps) versions prior to 9.0.48
Description
The WP Go Maps WordPress plugin does not properly sanitize user-supplied data submitted through an AJAX request. This allows unauthenticated users to inject and store cross-site scripting (XSS) payloads. These payloads are subsequently retrieved via another AJAX call and displayed without proper escaping, potentially leading to the execution of malicious scripts. The plugin is vulnerable because it fails to validate input before processing it, creating an opportunity for attackers to compromise the system.
Recommendations
Update WP Go Maps (formerly WP Google Maps) to version 9.0.48 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Go Maps
Wp Google Maps