CVE-2023-6777

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to unauthenticated API key disclosure in versions up to, and including, 9.0.34 due to the plugin adding the API key to several plugin files. This makes it possible for unauthenticated attackers to obtain the developer's Google API key. While this does not affect the security of sites using this plugin, it allows unauthenticated attackers to make requests using this API key with the potential of exhausting requests resulting in an inability to use the map functionality offered by the plugin.


We have discovered 24,131 live websites that are affected by CVE-2023-6777.

Test my site




Affected Software

Product  WP Go Maps
Category Wordpress Plugins
Vulnerable Domains24,131 live websites (48.21% of WP Go Maps install base)
Vulnerable Versions
  • from 0 through 9.0.34
Vulnerable Versions Count358 versions ( 94.71% of all versions)



Details

  • Published - Apr 9, 2024
  • Updated - Aug 8, 2024

Credits

  • Hassan Khan Yusufzai (finder)
  • Danish Tariq (finder)

CVE-2023-6777 usage by Country

United States7,100 websites



Germany3,461 websites
France2,059 websites
Poland1,335 websites
GB1,265 websites
Netherlands809 websites
Italy787 websites
Switzerland555 websites
Spain520 websites
Australia475 websites

CVE-2023-6777 usage by TLD

.com8,762 websites
.de2,063 websites
.pl1,102 websites
.co.uk1,095 websites
.fr970 websites
.org879 websites
.nl793 websites
.it645 websites
.com.au549 websites
.ch508 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-6777

Top websites that are affected by CVE-2023-6777. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.de Germany*,***
***********************.com United States**,***
******.net United States**,***
**********.com United States**,***
********.org United States**,***
***************.com United States**,***
***********.com United States***,***
**************.org United States***,***
******************.es Spain***,***
*******.org GB***,***
See full domain list

FAQ

A total of 24,131 websites have been identified as vulnerable to CVE-2023-6777, discovered through global website indexing conducted by WebTechSurvey.
WP Go Maps is susceptible to CVE-2023-6777 vulnerability.
WP Go Maps versions before, and including, 9.0.34 are vulnerable to CVE-2023-6777.