CVE-2026-9594: Flippercode Wp Maps – Google Maps,openstreetmap,mapbox,store Locator,listing,directory & Filters
Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location_messages' parameter in all versions up to, and including, 4.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the attacker to hold the custom wpgmp_manage_location capability, which is granted to administrators by default but can be assigned to lower-privileged roles via the plugin's Permissions screen.
Affected products
- Flippercode Wp Maps – Google Maps,openstreetmap,mapbox,store Locator,listing,directory & Filters: up to and including 4.9.4
Published 2026-06-06. Last modified 2026-07-23.