Wp Google Maps Pro: Cross-site scripting
Wp Google Maps Pro is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
- Component
- Wp Google Maps Pro
- Plugin slug
wp-google-maps-pro- Affected
- See vendor advisory
- Safe version
- See mitigation notes
- Published
- Sep 09, 2021
This CVE was published Sep 09, 2021 and is one of 2 known issues for this plugin.
Patch or disable the affected component.
Update Wp Google Maps Pro to a release outside the affected range, or disable and remove it until a fixed version is available.
Technical description
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in WordPress WP Google Maps Pro premium plugin (versions <= 8.1.11). Vulnerable parameters: &wpgmaps_marker_category_name, Value > &attributes[], Name > &attributes[], &icons[], &names[], &description, &link, &title.
CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
NVD vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N