---
id: CVE-2025-11703
title: >-
  The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to
  Cache Poisoning in all versions up to, and including, 9.0.48
summary: >-
  The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to
  Cache Poisoning in all versions up to, and including, 9.0.48. This is due to
  the plugin not serving cached data from server-side responses and instead
  relying…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-349
published: '2025-10-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11703'
references:
  - url: 'https://github.com/CodeCabin/wp-google-maps/pull/1087/files'
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3378871%40wp-google-maps&new=3378871%40wp-google-maps&sfp_email=&sfph_mail=
    label: security@wordfence.com
  - url: 'https://research.cleantalk.org/cve-2025-11703'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/531360c6-e78a-4344-be06-95735337a2d6?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00233
epssPercentile: 0.12995
ingestedAt: '2026-10-08T22:11:53.809Z'
---

## Overview

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 9.0.48. This is due to the plugin not serving cached data from server-side responses and instead relying on user-input. This makes it possible for unauthenticated attackers to poison the cache location for location search results.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
