PT-2025-46300 · WordPress · Wp Go Maps+1

Sunghoon Kim

·

Published

2025-11-11

·

Updated

2025-12-04

·

CVE-2025-11307

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Go Maps (formerly WP Google Maps) versions prior to 9.0.48
Description The WP Go Maps WordPress plugin does not properly sanitize user-supplied data submitted through an AJAX request. This allows unauthenticated users to inject and store cross-site scripting (XSS) payloads. These payloads are subsequently retrieved via another AJAX call and displayed without proper escaping, potentially leading to the execution of malicious scripts. The plugin is vulnerable because it fails to validate input before processing it, creating an opportunity for attackers to compromise the system.
Recommendations Update WP Go Maps (formerly WP Google Maps) to version 9.0.48 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-11307

Affected Products

Wp Go Maps
Wp Google Maps