CBX Map for Google Map & OpenStreetMap Security & Risk Analysis

wordpress.org/plugins/cbxgooglemap

Easy google map and open streetmap embed using shortcode, Responsive.

900 active installs v2.0.4 PHP + WP 5.3+ Updated Jan 4, 2026
elementor-addonsgoogle-mapgutenberg-blockopenstreetopenstreetmap
96
A · Safe
CVEs total4
Unpatched0
Last CVESep 10, 2025
Safety Verdict

Is CBX Map for Google Map & OpenStreetMap Safe to Use in 2026?

Generally Safe

Score 96/100

CBX Map for Google Map & OpenStreetMap has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Sep 10, 2025Updated 4mo ago
Risk Assessment

The cbxgooglemap plugin v2.0.4 exhibits a mixed security posture. While it demonstrates good practices in areas such as utilizing prepared statements for all SQL queries, a high percentage of output escaping, and a lack of critical or high-severity taint flows, significant concerns arise from its attack surface. Four out of five total entry points, specifically AJAX handlers, lack authentication checks. This exposes the plugin to potential unauthorized actions if these handlers can be triggered remotely. The vulnerability history shows a pattern of four known medium-severity CVEs, all related to Cross-Site Scripting (XSS). While none are currently unpatched, this history suggests a recurring weakness in input sanitization or output escaping that has been exploited in the past.

Despite the strengths in database interaction and output handling, the unprotected AJAX endpoints represent a clear and present danger. An attacker could potentially leverage these unprotected handlers to manipulate plugin functionality or extract information. The recurring medium-severity XSS vulnerabilities, even if patched, indicate a need for more robust input validation and output sanitization strategies to prevent future occurrences. The presence of the bundled Select2 library, while not explicitly flagged as an issue in the provided data, is worth noting as outdated versions of such libraries can sometimes introduce vulnerabilities.

In conclusion, cbxgooglemap v2.0.4 has commendable security practices regarding SQL and output escaping. However, the substantial number of unprotected AJAX handlers presents a critical risk that overshadows these positive aspects. The history of XSS vulnerabilities further underscores the need for continuous vigilance and improvement in securing all entry points. Users should exercise caution and ensure this plugin is kept up-to-date with any future security patches.

Key Concerns

  • Unprotected AJAX handlers found
  • History of medium severity XSS vulnerabilities
  • Bundled library (Select2) detected
Vulnerabilities
4 published

CBX Map for Google Map & OpenStreetMap Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2025-9123medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CBX Map for Google Map & OpenStreetMap <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 10, 2025 Patched in 2.0.2 (83d)
CVE-2025-47669medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CBX Map for Google Map & OpenStreetMap <= 1.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting

May 7, 2025 Patched in 2.0.0 (128d)
CVE-2024-22297medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CBX Map for Google Map & OpenStreetMap <= 1.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 17, 2024 Patched in 1.1.12 (52d)
CVE-2023-47240medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CBX Map for Google Map & OpenStreetMap <= 1.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Nov 7, 2023 Patched in 1.1.12 (123d)
Version History

CBX Map for Google Map & OpenStreetMap Release Timeline

Code Analysis
Analyzed Mar 16, 2026

CBX Map for Google Map & OpenStreetMap Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
59
578 escaped
Nonce Checks
6
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared4 total queries

Output Escaping

91% escaped637 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
metabox_save (includes\CBXGoogleMapAdmin.php:432)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

CBX Map for Google Map & OpenStreetMap Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_cbxgooglemap_settings_reset_loadincludes\CBXGoogleMap.php:154
authwp_ajax_cbxgooglemap_settings_resetincludes\CBXGoogleMap.php:155
authwp_ajax_cbxgooglemap_settings_importincludes\CBXGoogleMap.php:158
authwp_ajax_cbxgooglemap_settings_reset_sectionincludes\CBXGoogleMap.php:159

Shortcodes 1

[cbxgooglemap] includes\CBXGoogleMapPublic.php:179
WordPress Hooks 28
actionadmin_noticesincludes\CBXGoogleMap.php:85
actionplugins_loadedincludes\CBXGoogleMap.php:119
actionadmin_noticesincludes\CBXGoogleMap.php:120
filterplugin_row_metaincludes\CBXGoogleMap.php:122
actionactivated_pluginincludes\CBXGoogleMap.php:124
actioninitincludes\CBXGoogleMap.php:125
actionafter_plugin_row_cbxgooglemappro/cbxgooglemappro.phpincludes\CBXGoogleMap.php:126
actionadmin_initincludes\CBXGoogleMap.php:145
actioninitincludes\CBXGoogleMap.php:147
actionadmin_menuincludes\CBXGoogleMap.php:149
actionadd_meta_boxesincludes\CBXGoogleMap.php:151
actionsave_postincludes\CBXGoogleMap.php:153
actiontemplate_redirectincludes\CBXGoogleMap.php:157
filtermanage_edit-cbxgooglemap_columnsincludes\CBXGoogleMap.php:161
actionmanage_cbxgooglemap_posts_custom_columnincludes\CBXGoogleMap.php:162
actionadmin_enqueue_scriptsincludes\CBXGoogleMap.php:164
actionadmin_enqueue_scriptsincludes\CBXGoogleMap.php:165
actioninitincludes\CBXGoogleMap.php:168
filterblock_categories_allincludes\CBXGoogleMap.php:172
filterblock_categoriesincludes\CBXGoogleMap.php:174
actionenqueue_block_editor_assetsincludes\CBXGoogleMap.php:178
actioninitincludes\CBXGoogleMap.php:191
actionwidgets_initincludes\CBXGoogleMap.php:192
actionelementor/widgets/widgets_registeredincludes\CBXGoogleMap.php:195
actionelementor/elements/categories_registeredincludes\CBXGoogleMap.php:196
actionelementor/editor/before_enqueue_scriptsincludes\CBXGoogleMap.php:197
actionwp_enqueue_scriptsincludes\CBXGoogleMap.php:199
actionwp_enqueue_scriptsincludes\CBXGoogleMap.php:200
Maintenance & Trust

CBX Map for Google Map & OpenStreetMap Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 4, 2026
PHP min version
Downloads19K

Community Trust

Rating100/100
Number of ratings4
Active installs900
Developer Profile

CBX Map for Google Map & OpenStreetMap Developer Profile

Sabuj Kundu

10 plugins · 3K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
204 days
View full developer profile
Detection Fingerprints

How We Detect CBX Map for Google Map & OpenStreetMap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cbxgooglemap/assets/css/frontend.css/wp-content/plugins/cbxgooglemap/assets/js/frontend.js/wp-content/plugins/cbxgooglemap/assets/js/frontend.min.js/wp-content/plugins/cbxgooglemap/assets/css/backend.css/wp-content/plugins/cbxgooglemap/assets/css/backend.min.css
Version Parameters
cbxgooglemap/assets/css/frontend.css?ver=cbxgooglemap/assets/js/frontend.js?ver=cbxgooglemap/assets/js/frontend.min.js?ver=cbxgooglemap/assets/css/backend.css?ver=cbxgooglemap/assets/css/backend.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
cbx-google-map-wrappercbx-google-map-viewcbx-google-map-content
Data Attributes
data-cbx-google-map-id
Shortcode Output
[cbxgooglemap
FAQ

Frequently Asked Questions about CBX Map for Google Map & OpenStreetMap