Stored Cross-Site Scripting Vulnerability in WP Maps by WordPress
CVE-2026-13179

6.4MEDIUM

What is CVE-2026-13179?

The WP Maps plugin for WordPress is susceptible to a stored cross-site scripting vulnerability via the shapes_values parameter due to inadequate input sanitization and output escaping. Authenticated users with a subscriber-level role or higher can exploit this vulnerability by injecting malicious web scripts into pages. These scripts are executed whenever a user accesses the manipulated pages. Furthermore, the nonce value essential for secure operations is exposed to all users viewing a map page, allowing authenticated subscribers to craft requests easily. The vulnerability is exacerbated by the ability to bypass validations, thus posing significant risks to website integrity and user safety.

Affected Version(s)

WP Maps – Google Maps, OpenStreetMap, Mapbox, Store Locator with Search, Filters & Listings 0 <= 4.9.8

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.