Stored Cross-Site Scripting Vulnerability in WP Maps Plugin by WordPress
CVE-2025-13364

6.4MEDIUM

What is CVE-2025-13364?

The WP Maps – Store Locator and related plugins for WordPress are exposed to a stored cross-site scripting vulnerability due to inadequate input sanitization and output encoding on user-provided shortcode attributes. Authenticated attackers with contributor access can exploit this flaw by injecting malicious scripts within the content of pages, leading to the potential execution of these scripts when a user views the affected page. This vulnerability affects all versions up to and including 4.8.7, prompting immediate attention to patch security risks in the application.

Affected Version(s)

WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters 0 <= 4.8.7

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.