Stored Cross-Site Scripting in Leaflet Maps Marker Plugin for WordPress
CVE-2024-3670
6.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 2 May 2024
What is CVE-2024-3670?
The Leaflet Maps Marker plugin for WordPress contains a vulnerability that allows authenticated attackers with contributor-level access or higher to perform stored cross-site scripting attacks. This occurs through the plugin's 'mapsmarker' shortcode, which inadequately sanitizes and escapes user-supplied attributes, such as 'mapwidthunit'. As a result, attackers can inject arbitrary web scripts into pages, which will be executed in the browsers of users who visit the compromised pages.
Affected Version(s)
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) * <= 3.12.8