CVE-2024-29931
WordPress WP Go Maps plugin <= 9.0.29 - Reflected Cross Site Scripting (XSS) vulnerability
Record summary
CVE-2024-29931 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.29.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 25, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Through 9.0.29 | affected |
wp_go_mapsBrowse codecabin / wp_go_maps | VulnCheck | Version data not supplied | |
wp_go_mapsBrowse wp_go_maps / wp_go_mapsDefault status: unknown | CVE List | Through 9.0.29 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWP Go Maps <= 9.0.29 - Cross-Site ScriptingCVSS 6.1
WP Go Maps (formerly WP Google Maps) plugin for WordPress versions before 9.0.30 is vulnerable to Reflected Cross-Site Scripting via the 'map_id' parameter in the admin map edit page.
Impact
Attackers can execute arbitrary scripts in authenticated admin browsers, potentially leading to session hijacking, privilege escalation, WordPress admin account takeover, malicious plugin installation, and website defacement.
Remediation
Update WP Go Maps plugin to version 9.0.30 or later.
Source: ProjectDiscovery