Showing 1 vulnerability on this page for mapplic_lite

Signals CISA KEV Ransomware Nuclei
mapplic vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Mapplic Lite and Mapplic <= (Various Versions) - Server Side Request Forgery to Cross-Site Scirpting

The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS attack if requesting an SVG file.

CWE-918Oct 16, 20241 related artifact
CVSS8.3v3.1EPSS1.18%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX