PT-2026-4624 · WordPress · Wp Go Maps

Moose Love

·

Published

2026-01-24

·

Updated

2026-01-25

·

CVE-2026-0593

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Go Maps (formerly WP Google Maps) versions through 10.0.04
Description The WP Go Maps plugin for WordPress has an issue where data can be modified without proper authorization. This is due to a missing capability check within the processBackgroundAction() function. Attackers who are authenticated with Subscriber-level access or higher can change global map engine settings.
Recommendations Update WP Go Maps to a version later than 10.0.04.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-0593

Affected Products

Wp Go Maps