PT-2026-49184 · WordPress · Wp Go Maps
CVE-2026-8386
·
Published
2026-06-15
·
Updated
2026-07-16
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP Go Maps versions prior to 10.0.10
Description
The plugin fails to perform approval-state filtering on its public single-marker REST endpoint. This allows unauthenticated users to retrieve marker records that have not been approved by an administrator for public display. This information disclosure may include geographic coordinates and personally identifiable information (PII) contained within the address and description fields.
Recommendations
Update to version 10.0.10 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Go Maps