CVE-2020-36853: 10web Map Builder For Google Maps

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Affected products

  • 10web 10web Map Builder For Google Maps: before 1.0.64 (fixed in 1.0.64)

Published 2025-10-18. Last modified 2026-06-17.