Unauthenticated Cross Site Scripting in WP Google Maps Pro by WordPress
CVE-2026-57767

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 July 2026

What is CVE-2026-57767?

An unauthenticated Cross Site Scripting (XSS) vulnerability exists in WP Google Maps Pro versions 10.1.02 and below. This exploit allows attackers to inject malicious scripts, potentially affecting users when they interact with compromised content. Protect your WordPress site by ensuring you use the latest version and apply necessary security measures to prevent exploitation.

Affected Version(s)

WP Google Maps Pro <= 10.1.02

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Austin Ginder | Patchstack Bug Bounty Program
.