PT-2026-98381 · WordPress · Wp Amaps

·

CVE-2026-13179

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters versions prior to 4.9.9
Description Insufficient input sanitization and output escaping allow authenticated attackers with subscriber-level access and above to perform Stored Cross-Site Scripting (XSS), a technique where malicious scripts are permanently stored on the target server. Attackers can inject arbitrary web scripts via the shapes values parameter, which execute when a user visits the affected page. The fc-call-nonce nonce required by the endpoint is exposed to all frontend visitors through window.wpgmp local.nonce, allowing authenticated subscribers to craft valid requests. Furthermore, the secondary wpnonce check in the drawing handler can be bypassed by omitting the wpnonce parameter from the request.
Recommendations Update to version 4.9.9 or later. Avoid using the shapes values parameter until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13179

Affected Products

Wp Amaps