CVE-2019-10692: Codecabin Wp Go Maps
Critical severity, CVSS 9.8. EPSS: 78.7% chance of exploitation in the next 30 days.
In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize field names before a SELECT statement.
Affected products
- Codecabin Wp Go Maps: before 7.11.18 (fixed in 7.11.18)
Published 2019-04-02. Last modified 2026-06-17.