CVE 5.3 MEDIUM

WP Go Maps (formerly WP Google Maps) <= 9.0.48 - Unauthenticated Cache Poisoning_CVE-2025-11703

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.

Basic Information

ID CVE-2025-11703
Source Wordfence
Published Oct 18, 2025 at 06:42

Affected Product

Vendor wpgmaps
Product WP Go Maps (formerly WP Google Maps)
Version *
Affected Versions wpgmaps WP Go Maps (formerly WP Google Maps) *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.