Stored Cross-Site Scripting Vulnerability in Simple Map No Api Plugin for WordPress
CVE-2024-13565
5.4MEDIUM
What is CVE-2024-13565?
The Simple Map No Api plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability through the 'width' parameter. This flaw arises from inadequate input sanitization and output escaping, enabling authenticated users, including those with Contributor-level access, to inject arbitrary web scripts. These scripts are executed when other users access the compromised pages, posing significant risks to website security.
Affected Version(s)
Simple Map No Api * <= 1.9