Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 16 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flippercode
Flippercode google Map Flippercode wp Maps – Store Locator,google Maps,openstreetmap,mapbox,listing,directory & Filters Wordpress Wordpress wordpress |
|
| Vendors & Products |
Flippercode
Flippercode google Map Flippercode wp Maps – Store Locator,google Maps,openstreetmap,mapbox,listing,directory & Filters Wordpress Wordpress wordpress |
Thu, 16 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | |
| Title | WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-16T12:04:16.719Z
Reserved: 2025-11-18T16:57:46.868Z
Link: CVE-2025-13364
Updated: 2026-04-16T11:11:46.824Z
Status : Received
Published: 2026-04-16T07:16:28.550
Modified: 2026-04-16T07:16:28.550
Link: CVE-2025-13364
No data.
OpenCVE Enrichment
Updated: 2026-04-16T09:30:05Z