Reflected Cross-site Scripting Vulnerability in Google Map With Fancybox by uzzal mondal
CVE-2025-23594

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 February 2025

What is CVE-2025-23594?

A reflected Cross-site Scripting (XSS) vulnerability exists in the Google Map With Fancybox plugin developed by uzzal mondal. This issue allows attackers to inject malicious scripts through improper handling of user input during page generation. The vulnerability affects versions starting from n/a up to 2.1.0, enabling potential exploitation when users interact with compromised links, leading to unauthorized access and possible data theft.

Affected Version(s)

Google Map With Fancybox <= 2.1.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.
The Cyber Security Vulnerability Database.