Cross-Site Scripting Vulnerability in wp-google-maps Plugin for WordPress
CVE-2019-9912
6.1MEDIUM
What is CVE-2019-9912?
The wp-google-maps plugin prior to version 7.10.43 for WordPress contains a Cross-Site Scripting (XSS) vulnerability. This security flaw can be exploited via the wp-admin/admin.php PATH_INFO, allowing attackers to inject malicious scripts into the webpage context, potentially compromising user data and session integrity. Users are advised to update to the latest version to mitigate this risk.