Cross-Site Scripting Flaw in Embed Google Map by Petkivim
CVE-2025-26539
6.5MEDIUM
What is CVE-2025-26539?
The vulnerability involves an improper neutralization of input during web page generation, specifically allowing for stored Cross-site Scripting (XSS) in the Embed Google Map plugin by Petkivim. This flaw impacts all versions leading up to 3.2, potentially enabling malicious actors to inject harmful scripts into user-generated content, compromising the security and integrity of affected websites.
Affected Version(s)
Embed Google Map <= 3.2