Record summary

CVE-2025-11307 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJAX action, allowing unauthenticated users to store XSS payloads which are later retrieved from another AJAX call and output unescaped.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 4, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 12, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WP Go Maps (formerly WP Google Maps)

Default status: unaffected

CVE ListBefore 9.0.48affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWP Google Maps < 9.0.48 - Cross-Site ScriptingCVSS 8.8

WP Google Maps WordPress plugin < 9.0.48 contains a stored XSS vulnerability caused by unsanitized user input in AJAX actions, letting unauthenticated attackers execute scripts via stored payloads.

Impact

Unauthenticated attackers can execute arbitrary scripts in users' browsers, leading to session hijacking or defacement.

Remediation

Update to version 9.0.48 or later.

WeaknessesCWE-79
Authors0x_Akoko
Template tagscvecve2025wpwordpresswp-pluginxsscache-poisoningvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Shodan: http.html:"wp-google-maps"
FOFA: body="wp-google-maps"

Source: ProjectDiscovery

References

2