The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 11 Nov 2025 06:15:00 +0000

Type Values Removed Values Added
Description The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.
Title WP Google Maps < 9.0.48 - Unauthenticated Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-11-11T06:00:06.520Z

Reserved: 2025-10-04T20:19:25.432Z

Link: CVE-2025-11307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-11T06:15:34.890

Modified: 2025-11-11T06:15:34.890

Link: CVE-2025-11307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.