Record summary

CVE-2024-29931 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 25, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

WP Go Maps

Browse WPGMaps / WP Go Mapswp-google-maps

Default status: unaffected

CVE ListThrough 9.0.29affected
VulnCheckVersion data not supplied

Default status: unknown

CVE ListThrough 9.0.29affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWP Go Maps <= 9.0.29 - Cross-Site ScriptingCVSS 6.1

WP Go Maps (formerly WP Google Maps) plugin for WordPress versions before 9.0.30 is vulnerable to Reflected Cross-Site Scripting via the 'map_id' parameter in the admin map edit page.

Impact

Attackers can execute arbitrary scripts in authenticated admin browsers, potentially leading to session hijacking, privilege escalation, WordPress admin account takeover, malicious plugin installation, and website defacement.

Remediation

Update WP Go Maps plugin to version 9.0.30 or later.

WeaknessesCWE-79
AuthorsShivam Kamboj
Template tagscvecve2024wordpresswpwp-pluginxsswp-google-mapswp-go-mapsauthenticatedvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: ProjectDiscovery

References

3