Executive brief
WP Google Maps Pro, a popular WordPress plugin used to create and manage custom maps, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability can be exploited by remote attackers without needing any login credentials.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the WP Google Maps Pro plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link (User Interaction). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or the delivery of malicious content to other site visitors. The issue is resolved in version 10.1.03.
Affected products
- CodeCabin.io WP Google Maps Pro <= 10.1.02
Timeline
- 2026-05-26: other: Reported by Austin Ginder
- 2026-07-10: advisory: Patchstack advisory published
- 2026-07-23: disclosed: NVD publication date
- 2026-07-10: patched: Version 10.1.03 released