XML Injection Vulnerability in Easy Google Maps by Supsystic
CVE-2025-32138

6.6MEDIUM

Key Information:

Vendor

Supsystic

Vendor
CVE Published:
4 April 2025

What is CVE-2025-32138?

An improper restriction of XML External Entity (XXE) reference vulnerability exists in the Easy Google Maps plugin by Supsystic, allowing for potential XML Injection attacks. This flaw can be exploited by an attacker to manipulate XML processing and gain unauthorized access to sensitive data or services. The issue affects all versions up to and including 1.11.17, necessitating prompt attention to ensure the security of web applications using this plugin.

Affected Version(s)

Easy Google Maps 0 <= 1.11.18

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

minhtuanact (Patchstack Alliance)
.