PT-2026-49184 · WordPress · Wp Go Maps

CVE-2026-8386

·

Published

2026-06-15

·

Updated

2026-07-16

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Go Maps versions prior to 10.0.10
Description The plugin fails to perform approval-state filtering on its public single-marker REST endpoint. This allows unauthenticated users to retrieve marker records that have not been approved by an administrator for public display. This information disclosure may include geographic coordinates and personally identifiable information (PII) contained within the address and description fields.
Recommendations Update to version 10.0.10 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-8386

Affected Products

Wp Go Maps