
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Security & Risk Analysis
wordpress.org/plugins/wp-google-map-pluginWordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
Is WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Safe to Use in 2026?
Generally Safe
Score 88/100WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-google-map-plugin" v4.9.2 exhibits a mixed security posture. While it demonstrates good practices with a high percentage of prepared SQL statements and properly escaped output, there are significant concerns related to its attack surface and past vulnerability history. The presence of 10 AJAX handlers, with 2 lacking authentication checks, presents a direct entry point for potential exploitation. Furthermore, the taint analysis revealed one high-severity flow, indicating a potential for serious security issues if not properly handled. The plugin's history of 20 CVEs, particularly the high number of high and medium severity vulnerabilities, including path traversal, SQL injection, XSS, deserialization, and CSRF, suggests a recurring pattern of security weaknesses. While there are currently no unpatched CVEs, the historical prevalence of these critical vulnerability types warrants caution. The use of Select2, a bundled library, could also pose a risk if it's an outdated or vulnerable version. Overall, the plugin has some strengths in its code handling but is significantly undermined by its attack surface and historical susceptibility to severe vulnerabilities.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flow
- History of 9 high severity CVEs
- History of 11 medium severity CVEs
- Bundled library (Select2)
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Security Vulnerabilities
CVEs by Year
Severity Breakdown
20 total CVEs
WP Maps <= 4.9.1 - Unauthenticated SQL Injection via 'location_id' Parameter
WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion
Maps <= 4.8.6 - Authenticated (Administrator+) PHP Object Injection
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Maps – Display Google Maps Perfectly with Ease <= 4.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
WordPress Plugin for Google Maps – WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection
WP Google Map Plugin <= 4.4.2 - Cross-Site Request Forgery via delete()
WP MAPS <= 4.3.9 - Authenticated (Editor+) Stored Cross-Site Scripting
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.2.3 - Cross-Site Request Forgery
WP Google Map Plugin <= 4.1.4 - Authenticated SQL Injection via Orderby
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps <= 4.0.9 - Reflected Cross-Site Scripting
WP Google Map Plugin <= 4.0.9 - Cross-Site Request Forgery to PHP Object Injection
WP MAPS – Easiest & Most Advanced WordPress Plugin for Google Maps < 4.0.4 - Cross-Site Scripting
WP Google Map Plugin <= 3.1.1 - Cross-Site Scripting
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
WP Google Map Plugin < 2.3.10 - Cross-Site Request Forgery
WP Google Map Plugin < 3.0.0 - Cross-Site Request Forgery to Cross-Site Scripting
WP Google Map Plugin < 2.3.7 - Reflected Cross-Site Scripting
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 50
Scheduled Events 1
Maintenance & Trust
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Maintenance & Trust
Maintenance Signals
Community Trust
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Alternatives
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map
easy-map
Create interactive maps with store locator, markers, drawings & multiple locations. Supports OpenStreetMap and Google Maps. No API key needed.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Maps Plugin using Google Maps for WordPress – WP Google Map
gmap-embed
Google Map plugin for WordPress is very Simple, light-weight and Easy to use Google Custom Map with markers in Posts, Pages, Sidebar as shortcode.
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Developer Profile
4 plugins · 63K total installs
How We Detect WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-google-map-plugin/assets/css/frontend.css/wp-content/plugins/wp-google-map-plugin/assets/css/jquery.dataTables.min.css/wp-content/plugins/wp-google-map-plugin/assets/css/map.css/wp-content/plugins/wp-google-map-plugin/assets/css/owl.carousel.min.css/wp-content/plugins/wp-google-map-plugin/assets/css/responsive.css/wp-content/plugins/wp-google-map-plugin/assets/css/style.css/wp-content/plugins/wp-google-map-plugin/assets/js/admin-map.js/wp-content/plugins/wp-google-map-plugin/assets/js/admin-scripts.js+9 more/wp-content/plugins/wp-google-map-plugin/assets/js/admin-scripts.js/wp-content/plugins/wp-google-map-plugin/assets/js/frontend.js/wp-content/plugins/wp-google-map-plugin/assets/js/google-maps-api.js/wp-content/plugins/wp-google-map-plugin/assets/js/wpgmp-scripts.js/wp-content/plugins/wp-google-map-plugin/assets/js/wpgmp-tinymce.jswp-google-map-plugin/assets/css/frontend.css?ver=wp-google-map-plugin/assets/css/map.css?ver=wp-google-map-plugin/assets/css/style.css?ver=wp-google-map-plugin/assets/js/frontend.js?ver=wp-google-map-plugin/assets/js/google-maps-api.js?ver=wp-google-map-plugin/assets/js/wpgmp-scripts.js?ver=HTML / DOM Fingerprints
wpgmp_map_canvaswpgmp_marker_info_windowwpgmp_map_markers_listwpgmp_map_wrapperwpgmp_marker_titlewpgmp_marker_addresswpgmp_marker_descriptionwpgmp_map_listing_title+8 more<!-- wp google map plugin --><!-- WPGoogleMaps --><!-- wp google map plugin --><!-- Developed by Flipper Code -->+2 moredata-map-iddata-marker-iddata-latdata-lngdata-icondata-title+4 moreWPGMP_SettingsWPGMP_Admin_Mapwpgmp_map_admin_scriptsWPGMP_Frontend_Mapwpgmp_frontend_scriptswpgmp_tinymce_plugin[put_wpgm]