API KEY for Google Maps
API KEY for Google Maps has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 5.4 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for API KEY for Google Maps has a vendor fix available, so running the current release closes it.
API KEY for Google Maps is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2022-29453API KEY for Google Maps <= 1.2.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

API KEY for Google Maps
Author
Stiofan
Retroactively add Google Maps API KEY to any theme or plugin. Simply activate, go to Settings>Google API KEY and enter your key. The plugin will then attempt to add this key to all the places it is needed on the front of your website. NOTE: this will only work if the Google API has been added as per WordPress standards) Since January 2023 Google Maps JavaScript API requires callback parameter. This plugin also fixes JavaScript Error: Loading the Google Maps JavaScript API without a callback is not supported. The plugin was created by the GeoDirectory team: https://wpgeodirectory.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C