Back to overview

CVE-2026-8386

Description
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved for public display, including any PII placed in the address and description fields and the marker's geographic coordinates.

Metadata

CVE ID
CVE-2026-8386
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-12 11:26 UTC
Published
2026-06-15 06:00 UTC
Last updated
2026-06-15 06:00 UTC
Vendor / Product
Unknown / WP Go Maps
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown WP Go Maps 0 < 10.0.10
Weakness (CWE)
CWESourceDescription
cna CWE-200 Information Exposure
Back to overview