PT-2026-49184 · WordPress · Wp Go Maps

Published

2026-06-15

·

Updated

2026-06-15

·

CVE-2026-8386

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions WP Go Maps versions prior to 10.0.10
Description The plugin fails to perform approval-state filtering on its public single-marker REST endpoint. This allows unauthenticated users to retrieve marker records that have not been approved by an administrator for public display. This information disclosure may include geographic coordinates and personally identifiable information (PII) contained within the address and description fields.
Recommendations Update to version 10.0.10 or later.

Exploit

Related Identifiers

CVE-2026-8386

Affected Products

Wp Go Maps