Stored Cross-Site Scripting in Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite Plugin by WordPress
CVE-2023-3412
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2023
What is CVE-2023-3412?
The Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress is vulnerable to stored cross-site scripting attacks due to a missing capability check in the ajax_store_save() function. This vulnerability allows authenticated attackers, even those with minimal privileges such as subscribers, to modify plugin settings and inject harmful scripts into the application, potentially leading to significant security risks for users.
Affected Version(s)
Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite * <= 1.0.0