Unauthenticated Broken Access Control in WP Go Maps by WordPress
CVE-2026-25466
5.3MEDIUM
What is CVE-2026-25466?
The WP Go Maps plugin for WordPress versions up to 10.1.04 is affected by unauthenticated broken access control vulnerabilities, allowing unauthorized users to gain access to sensitive functionalities or data. This can lead to privilege escalation, enabling attackers to manipulate or retrieve data without proper authorization safeguards in place. User data integrity and application security may be significantly compromised, highlighting the need for immediate updates to mitigate potential exploits.
Affected Version(s)
WP Go Maps <= 10.1.04