Junglewise Threat Intelligence

CVE-2026-9594: WP Maps WordPress plugin Stored XSS in location_messages parameter

CVE-2026-9594 · Severity: medium · CVSS 4.4 · Published 2026-06-06

Technologies: WP Maps. Vendors: WP Maps.

Executive brief

A vulnerability exists in the WP Maps plugin for WordPress, which is used to display interactive maps and store locators on websites. An attacker with administrative or specific manager permissions can inject malicious scripts into map location settings. These scripts will then execute in the browser of any user who visits the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'location_messages' parameter. This vulnerability exists in all versions up to and including 4.9.4. An authenticated attacker with the 'wpgmp_manage_location' capability (typically administrators) can inject arbitrary web scripts into the database. These scripts are then executed in the context of a user's browser session when they access the page where the malicious payload is rendered. While it requires high privileges by default, these permissions can be delegated to lower-privileged roles via the plugin's internal settings.

Affected products

  • WP Maps WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator, Listing, Directory & Filters Up to and including 4.9.4

Timeline

  • 2026-06-06: disclosed
  • 2026-06-06: advisory

References

Related threats