Stored Cross-Site Scripting in Coon Google Maps Plugin for WordPress
CVE-2025-12662
6.4MEDIUM
What is CVE-2025-12662?
The Coon Google Maps plugin for WordPress exhibits a vulnerability where insufficient input sanitization and output escaping on the 'height' parameter of the 'map' shortcode allows authenticated attackers with contributor-level access or higher to inject malicious scripts. This could lead to arbitrary web scripts executing on pages viewed by users, compromising the integrity and security of the affected websites.
Affected Version(s)
Coon Google Maps * <= 1.0