
CBX Map for Google Map & OpenStreetMap Security & Risk Analysis
wordpress.org/plugins/cbxgooglemapEasy google map and open streetmap embed using shortcode, Responsive.
Is CBX Map for Google Map & OpenStreetMap Safe to Use in 2026?
Generally Safe
Score 96/100CBX Map for Google Map & OpenStreetMap has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The cbxgooglemap plugin v2.0.4 exhibits a mixed security posture. While it demonstrates good practices in areas such as utilizing prepared statements for all SQL queries, a high percentage of output escaping, and a lack of critical or high-severity taint flows, significant concerns arise from its attack surface. Four out of five total entry points, specifically AJAX handlers, lack authentication checks. This exposes the plugin to potential unauthorized actions if these handlers can be triggered remotely. The vulnerability history shows a pattern of four known medium-severity CVEs, all related to Cross-Site Scripting (XSS). While none are currently unpatched, this history suggests a recurring weakness in input sanitization or output escaping that has been exploited in the past.
Despite the strengths in database interaction and output handling, the unprotected AJAX endpoints represent a clear and present danger. An attacker could potentially leverage these unprotected handlers to manipulate plugin functionality or extract information. The recurring medium-severity XSS vulnerabilities, even if patched, indicate a need for more robust input validation and output sanitization strategies to prevent future occurrences. The presence of the bundled Select2 library, while not explicitly flagged as an issue in the provided data, is worth noting as outdated versions of such libraries can sometimes introduce vulnerabilities.
In conclusion, cbxgooglemap v2.0.4 has commendable security practices regarding SQL and output escaping. However, the substantial number of unprotected AJAX handlers presents a critical risk that overshadows these positive aspects. The history of XSS vulnerabilities further underscores the need for continuous vigilance and improvement in securing all entry points. Users should exercise caution and ensure this plugin is kept up-to-date with any future security patches.
Key Concerns
- Unprotected AJAX handlers found
- History of medium severity XSS vulnerabilities
- Bundled library (Select2) detected
CBX Map for Google Map & OpenStreetMap Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
CBX Map for Google Map & OpenStreetMap <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
CBX Map for Google Map & OpenStreetMap <= 1.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting
CBX Map for Google Map & OpenStreetMap <= 1.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
CBX Map for Google Map & OpenStreetMap <= 1.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
CBX Map for Google Map & OpenStreetMap Release Timeline
CBX Map for Google Map & OpenStreetMap Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CBX Map for Google Map & OpenStreetMap Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
CBX Map for Google Map & OpenStreetMap Maintenance & Trust
Maintenance Signals
Community Trust
CBX Map for Google Map & OpenStreetMap Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
leaflet-maps-marker
The most comprehensive & user-friendly mapping solution for WordPress
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
Map Engine – Google Maps and Open Street Maps for WordPress
map-engine
An Ultimate map tool to revolutionize your map building experience.
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map
easy-map
Create interactive maps with store locator, markers, drawings & multiple locations. Supports OpenStreetMap and Google Maps. No API key needed.
CBX Map for Google Map & OpenStreetMap Developer Profile
10 plugins · 3K total installs
How We Detect CBX Map for Google Map & OpenStreetMap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cbxgooglemap/assets/css/frontend.css/wp-content/plugins/cbxgooglemap/assets/js/frontend.js/wp-content/plugins/cbxgooglemap/assets/js/frontend.min.js/wp-content/plugins/cbxgooglemap/assets/css/backend.css/wp-content/plugins/cbxgooglemap/assets/css/backend.min.csscbxgooglemap/assets/css/frontend.css?ver=cbxgooglemap/assets/js/frontend.js?ver=cbxgooglemap/assets/js/frontend.min.js?ver=cbxgooglemap/assets/css/backend.css?ver=cbxgooglemap/assets/css/backend.min.css?ver=HTML / DOM Fingerprints
cbx-google-map-wrappercbx-google-map-viewcbx-google-map-contentdata-cbx-google-map-id[cbxgooglemap