packetstormsecurity.com
http://packetstormsecurity.com/files/163261/WordPress-WP-Google-Maps-8.1.11-Cross-Site-Scripting.html CVE-2021-24383
MEDIUM
WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)
Record summary
CVE-2021-24383 has a selected CVSS score of 5.4 (medium); EIP currently links 1 catalogued exploit.
Description
The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Google MapsBrowse WP Google Maps / WP Google Maps | CVE List | 8.1.12 to < 8.1.12 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin WP Google Maps 8.1.11 - Stored Cross-Site Scripting (XSS)ExploitDB exploitby Mohammed AdamNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-24383 wpscan.comConfirmation
https://wpscan.com/vulnerability/1270588c-53fe-447e-b83c-1b877dc7a954