Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma WordPress Google Map Professional google-map-professional allows SQL Injection.This issue affects WordPress Google Map Professional: from n/a through <= 1.0.
Published: 2025-01-16
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress Google Map Professional plugin contains an SQL Injection vulnerability that allows attackers to supply unfiltered input that is incorporated into SQL statements. Because the plugin does not properly neutralize special characters, an attacker could read, modify, or delete data stored in the database. The impact is limited to database integrity and confidentiality; there is no evidence of direct code execution but the loss of data could be significant.

Affected Systems

Vulnerable systems include any WordPress installation running the WordPress Google Map Professional plugin version 1.0 or earlier, identified in the vendor’s product list as pankajpragma WordPress Google Map Professional. The affected version range is from n/a through <=1.0, meaning all releases up to and including 1.0 are impacted.

Risk and Exploitability

The CVSS score of 8.5 denotes high severity, but the EPSS score of less than 1% indicates a very low estimated exploitation probability at the time of analysis. The plugin’s entry points are web-based, so the likely attack vector is through HTTP requests to the plugin’s endpoints; the exploit would require the ability to send SQL payloads through the plugin’s input parameters. The vulnerability is currently not listed in CISA’s KEV catalog. Security teams should treat it as high risk but acknowledge the low likelihood of active exploitation.

Generated by OpenCVE AI on May 1, 2026 at 20:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WordPress Google Map Professional plugin to a version that removes the SQL Injection flaw.
  • If an upgrade is unavailable, uninstall or disable the plugin to eliminate the attack surface.
  • Configure your web application firewall or security plugins to block or filter suspicious SQL injection payloads targeting the plugin’s input fields.

Generated by OpenCVE AI on May 1, 2026 at 20:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3528 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma, rahulpragma WordPress Google Map Professional allows SQL Injection.This issue affects WordPress Google Map Professional: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma, rahulpragma WordPress Google Map Professional allows SQL Injection.This issue affects WordPress Google Map Professional: from n/a through 1.0. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma WordPress Google Map Professional google-map-professional allows SQL Injection.This issue affects WordPress Google Map Professional: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pankajpragma, rahulpragma WordPress Google Map Professional allows SQL Injection.This issue affects WordPress Google Map Professional: from n/a through 1.0.
Title WordPress Google Map Professional Plugin <= 1.0 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T22:40:32.429Z

Reserved: 2025-01-16T11:32:12.975Z

Link: CVE-2025-23913

cve-icon Vulnrichment

Updated: 2025-01-17T17:16:07.842Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:33.100

Modified: 2026-06-17T08:57:43.240

Link: CVE-2025-23913

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T20:30:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')