CVE-2020-36853

10WebMapBuilder <= 1.0.63 - Unauthenticated Stored Cross-Site Scripting via Plugin Settings Change

The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in versions up to, and including, 1.0.63 due to insufficient input sanitization and output escaping and a lack of capability checks. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 1,981 live websites that are affected by CVE-2020-36853.

Run a Free Instant Scan




Affected Software

Product  Wd Google Maps
Category Wordpress Plugins
Vulnerable Domains1,981 live websites (100% of Wd Google Maps install base)
Vulnerable Versions
  • from 0 through 1.0.64
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Oct 18, 2025
  • Updated - Oct 20, 2025

Credits

  • Mikey Veenstra (finder)

Website Distribution by Country

Number of websites using CVE-2020-36853
United States415 websites



Germany239 websites
France160 websites
Italy118 websites
GB97 websites
Poland75 websites
Netherlands66 websites
Japan52 websites
Switzerland47 websites
Brazil40 websites

Website Distribution by TLD

Number of websites using CVE-2020-36853
.com689 websites
.de131 websites
.it84 websites
.fr80 websites
.org74 websites
.co.uk56 websites
.nl56 websites
.pl55 websites
.ch44 websites
.net43 websites

Websites affected by CVE-2020-36853

Top websites that are affected by CVE-2020-36853. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.app Germany**,***
****.*****.edu United States***,***
***.***.uk United States***,***
****.org United States***,***
****************.***.uk United States***,***
********.com Russia***,***
******.de Germany***,***
*********.fr Russia***,***
********.com United States***,***
********.com Japan***,***
See full domain list

FAQ

CVE-2020-36853 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wd Google Maps
A total of 1,981 websites have been identified as vulnerable to CVE-2020-36853, based on global website indexing conducted by WebTechSurvey.
The Wd Google Maps is affected by the CVE-2020-36853 vulnerability.
Wd Google Maps versions up to 1.0.64 are vulnerable to CVE-2020-36853.
CVE-2020-36853 is resolved in version 1.0.64 of Wd Google Maps.