Reflected Cross-Site Scripting in WP Go Maps Plugin from WordPress
CVE-2023-6697

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
24 January 2024

Summary

The WP Go Maps plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) due to inadequate sanitization of input parameters, specifically the map id parameter. This vulnerability affects all installations of the plugin up to version 9.0.28. Attackers can exploit this flaw by crafting a malicious link that, when clicked by a user, will execute arbitrary scripts in their browser context, compromising user data and security.

Affected Version(s)

WP Go Maps (formerly WP Google Maps) * <= 9.0.28

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nex Team
.