CVE-2025-11307
WP Google Maps < 9.0.48 - Unauthenticated Stored XSS
Record summary
CVE-2025-11307 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WP Go Maps (formerly WP Google Maps)Default status: unaffected | CVE List | Before 9.0.48 | affected |
wp_go_mapsBrowse codecabin / wp_go_maps | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryHIGHWP Google Maps < 9.0.48 - Cross-Site ScriptingCVSS 8.8
WP Google Maps WordPress plugin < 9.0.48 contains a stored XSS vulnerability caused by unsanitized user input in AJAX actions, letting unauthenticated attackers execute scripts via stored payloads.
Impact
Unauthenticated attackers can execute arbitrary scripts in users' browsers, leading to session hijacking or defacement.
Remediation
Update to version 9.0.48 or later.
Source: ProjectDiscovery