Executive brief
WP Go Maps, a popular WordPress plugin used for creating custom maps, contains a security flaw that allows unauthorized individuals to access restricted functions. Because this vulnerability involves broken access control, an attacker could potentially view sensitive information or perform actions that should be reserved for site administrators. This could lead to unauthorized data exposure or minor disruptions to the website's mapping features.
Technical details
A broken access control vulnerability exists in the WP Go Maps plugin for WordPress (versions up to and including 10.1.04). The flaw is rooted in missing authorization checks (CWE-862), allowing an unauthenticated remote attacker to execute functions that should require higher privileges. According to the CVSS vector, the impact is limited to low confidentiality loss, suggesting an attacker might be able to retrieve data but not necessarily modify site content or take full control. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from the developer.
Affected products
- WPGMaps WP Go Maps <= 10.1.04
Timeline
- 2025-12-18: other: Reported by researcher Bao - BlueRock
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD dataset