Stored Cross-Site Scripting Vulnerability in MapPress Maps for WordPress
CVE-2023-6524
5.4MEDIUM
Summary
The MapPress Maps for WordPress plugin is susceptible to Stored Cross-Site Scripting through inadequate sanitization and escaping of the map title parameter. This vulnerability affects all versions up to and including 2.88.13. Authenticated users with contributor access or higher can exploit this weakness by injecting malicious scripts, leading to execution whenever a user interacts with an affected page, posing significant risks to website integrity and user safety.
Affected Version(s)
MapPress Maps for WordPress * <= 2.88.13
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Akbar Kustirama