The WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator, Listing, Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.8. Authenticated attackers with subscriber-level access and above can include and execute arbitrary .php files on the server, allowing PHP code execution. This can be used to bypass access controls, obtain sensiti [truncated]
The WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator, Listing, Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shapes_values parameter in all versions up to, and including, 4.9.8. This vulnerability allows authenticated attackers with subscriber-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesse [truncated]