Input validation vulnerability in WP Go Maps (formerly WP Google Maps) 9.0.27

The WP Go Maps plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This vulnerability affects all versions of the plugin up to and including 9.0.27. It is possible for unauthenticated attackers to inject malicious web scripts into pages, which will then be executed whenever a user visits the page. This is due to the plugin not properly sanitizing user input and not properly escaping output.

Detected in:

WP Go Maps (formerly WP Google Maps) fixed vulnerable versions: >= * <= 9.0.27

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.