Stored XSS Vulnerability in WP Baidu Map Plugin
CVE-2024-9886
What is CVE-2024-9886?
The WP Baidu Map plugin for WordPress exhibits a vulnerability that allows for Stored Cross-Site Scripting (XSS) due to inadequate input validation and output escaping of user-supplied attributes through the 'baidu_map' shortcode. This security flaw permits authenticated attackers with at least contributor-level access to infuse arbitrary web scripts into web pages. When users access these compromised pages, the injected scripts execute, posing significant risks to site integrity and user data. It is crucial for WordPress administrators and site owners to ensure their plugins are up-to-date and follow security best practices to mitigate such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Baidu Map * <= 1.2.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved