Stored Cross-Site Scripting Vulnerability in WP Maps by WordPress
CVE-2026-13179
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2026
What is CVE-2026-13179?
The WP Maps plugin for WordPress is susceptible to a stored cross-site scripting vulnerability via the shapes_values parameter due to inadequate input sanitization and output escaping. Authenticated users with a subscriber-level role or higher can exploit this vulnerability by injecting malicious web scripts into pages. These scripts are executed whenever a user accesses the manipulated pages. Furthermore, the nonce value essential for secure operations is exposed to all users viewing a map page, allowing authenticated subscribers to craft requests easily. The vulnerability is exacerbated by the ability to bypass validations, thus posing significant risks to website integrity and user safety.
Affected Version(s)
WP Maps β Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings 0 <= 4.9.8