Stored Cross-Site Scripting Vulnerability in WP Maps Plugin by WordPress
CVE-2025-13364
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 April 2026
What is CVE-2025-13364?
The WP Maps β Store Locator and related plugins for WordPress are exposed to a stored cross-site scripting vulnerability due to inadequate input sanitization and output encoding on user-provided shortcode attributes. Authenticated attackers with contributor access can exploit this flaw by injecting malicious scripts within the content of pages, leading to the potential execution of these scripts when a user views the affected page. This vulnerability affects all versions up to and including 4.8.7, prompting immediate attention to patch security risks in the application.
Affected Version(s)
WP Maps β Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters 0 <= 4.8.7