The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. This CVE record was published on 2026-07-31T07:16:27.143Z and has not been modified since then. The vulnerability has a CVSS score of 3.7, indicating a low severity. Users of the WP Go Maps WordPress plugin should [truncated]
The WP Go Maps WordPress plugin before version 10.0.10 has an information disclosure vulnerability. This vulnerability exists in its public single-marker REST endpoint, where it fails to perform approval-state filtering. As a result, unauthenticated users can retrieve marker records that have not been approved for public display by an administrator. This includes personally identifiable information (PII) [truncated]