Reflected Cross-Site Scripting in WP Go Maps Plugin from WordPress
CVE-2023-6697
6.1MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 24 January 2024
Summary
The WP Go Maps plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) due to inadequate sanitization of input parameters, specifically the map id parameter. This vulnerability affects all installations of the plugin up to version 9.0.28. Attackers can exploit this flaw by crafting a malicious link that, when clicked by a user, will execute arbitrary scripts in their browser context, compromising user data and security.
Affected Version(s)
WP Go Maps (formerly WP Google Maps) * <= 9.0.28
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nex Team