Executive brief
Gmaper for Elementor is a WordPress plugin for embedding and managing Google Maps within web pages using the Elementor page builder. A broken access control vulnerability allows subscribers to view or perform actions they should not be permitted to access, such as viewing other users' private data or maps. This could expose sensitive website information and compromise user privacy.
Technical details
The vulnerability is a broken access control issue (CWE-284) that affects Gmaper for Elementor versions up to 1.0.9. The plugin fails to properly enforce authorization checks on certain actions or pages, allowing authenticated users with subscriber-level privileges to access restricted functionality or data. The vulnerability requires an authenticated user account (subscriber role minimum) to exploit. An attacker with subscriber access could view or modify pages or data belonging to other users. No official patch is currently available as of the published date.
Affected products
- Merkulove Gmaper for Elementor through 1.0.9
Timeline
- 2025-11-10: disclosed: Reported by Phat RiO
- 2025-12-31: advisory: Published by Patchstack and disclosed on NVD