The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered by the plugin.
We have discovered 24,131 live websites that are affected by CVE-2023-6777.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 24,131 live websites (48.21% of WP Go Maps install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 358 versions ( 94.71% of all versions) |
![]() | 7,100 websites |
![]() | 3,461 websites |
![]() | 2,059 websites |
![]() | 1,335 websites |
![]() | 1,265 websites |
![]() | 809 websites |
![]() | 787 websites |
![]() | 555 websites |
![]() | 520 websites |
![]() | 475 websites |
.com | 8,762 websites |
.de | 2,063 websites |
.pl | 1,102 websites |
.co.uk | 1,095 websites |
.fr | 970 websites |
.org | 879 websites |
.nl | 793 websites |
.it | 645 websites |
.com.au | 549 websites |
.ch | 508 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.de | ![]() | *,*** | |
***********************.com | ![]() | **,*** | |
******.net | ![]() | **,*** | |
**********.com | ![]() | **,*** | |
********.org | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
***********.com | ![]() | ***,*** | |
**************.org | ![]() | ***,*** | |
******************.es | ![]() | ***,*** | |
*******.org | ![]() | ***,*** |
FAQ