Cross Site Scripting Vulnerability in Easy Google Maps Plugin by WordPress
CVE-2026-102395
7.1HIGH
What is CVE-2026-102395?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in the Easy Google Maps plugin for WordPress, impacting versions 1.14.6 and earlier. This flaw allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to information theft and unauthorized actions. It is imperative for users of the plugin to update to a secure version to mitigate risks.
Affected Version(s)
Easy Google Maps <= 1.14.6