Reflected Cross-Site Scripting in WP Go Maps Plugin from WordPress
CVE-2023-6697
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 January 2024
What is CVE-2023-6697?
The WP Go Maps plugin for WordPress is susceptible to Reflected Cross-Site Scripting (XSS) due to inadequate sanitization of input parameters, specifically the map id parameter. This vulnerability affects all installations of the plugin up to version 9.0.28. Attackers can exploit this flaw by crafting a malicious link that, when clicked by a user, will execute arbitrary scripts in their browser context, compromising user data and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Go Maps (formerly WP Google Maps) * <= 9.0.28
References
EPSS Score
54% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved