CVE-2026-15381

NONE EPSS 0.18%
Updated Jul 31, 2026
Unknown
Parameter Value
Affected Versions before 10.1.04
Type CWE-89 SQL Injection
Vendor Unknown
Public PoC No

The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Weakness Type (CWE)

Vulnerable Products

unknown:wp go maps