WordPress Plugin Vulnerabilities

WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback

Description

The plugin does not properly enforce the marker approval filter on the admin-ajax fallback for its datatables route, allowing unauthenticated visitors to retrieve marker records that the site owner has not approved for public display, including their title, category, address and description fields.

Proof of Concept

Affects Plugins

Fixed in 10.0.10

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Sudhanshu Chauhan [RedHunt Labs]
Submitter
Sudhanshu Chauhan [RedHunt Labs]
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-05-25 (about 21 days ago)
Added
2026-05-25 (about 20 days ago)
Last Updated
2026-05-25 (about 20 days ago)

Other