PatchSiren

WP Go Maps CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW WP Go Maps CVE published 2026-07-31

CVE-2026-15381

The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. This CVE record was published on 2026-07-31T07:16:27.143Z and has not been modified since then. The vulnerability has a CVSS score of 3.7, indicating a low severity. Users of the WP Go Maps WordPress plugin should [truncated]

MEDIUM WP Go Maps CVE published 2026-06-15

CVE-2026-8386

The WP Go Maps WordPress plugin before version 10.0.10 has an information disclosure vulnerability. This vulnerability exists in its public single-marker REST endpoint, where it fails to perform approval-state filtering. As a result, unauthenticated users can retrieve marker records that have not been approved for public display by an administrator. This includes personally identifiable information (PII) [truncated]