Stored Cross-Site Scripting in Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite Plugin by WordPress
CVE-2023-3412

5.4MEDIUM

Key Information:

Summary

The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to stored cross-site scripting attacks due to a missing capability check in the ajax_store_save() function. This vulnerability allows authenticated attackers, even those with minimal privileges such as subscribers, to modify plugin settings and inject harmful scripts into the application, potentially leading to significant security risks for users.

Affected Version(s)

Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite * <= 1.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.