MEDIUM
Maps - Google Maps <= 1.0.6 - Contributor+ Stored XSS
Published Apr 4, 2025
5.9
MEDIUMCVSS 3.1
EPSS 0.27%
Description
The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected products
- Vendor n/a Product Maps Defaultaffected
- Version 0StatusaffectedConstraints<=1.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Maps | affected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-9687 Advisory
- https://wpscan.com/vulnerability/cd87d7ba-86e9-45b6-a3cd-11f6486f0bd0/ exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-9687 | Advisory | |
| https://wpscan.com/vulnerability/cd87d7ba-86e9-45b6-a3cd-11f6486f0bd0/ | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Apr 4, 2025
Updated Apr 4, 2025
Reserved Mar 13, 2025
Link CVE-2025-2279
CISA Vulnrichment
Updated Apr 4, 2025
ENISA EUVD
EUVD-2025-9687 Assigner WPScan
Published Apr 4, 2025
Updated Apr 4, 2025
Exploited since n/a
Link EUVD-2025-9687