cleantalk
Vulnerabilities and Security Researches

Maps Plugin using Google Maps for WordPress – WP Google Map, CVE-2021-24502

CVE, Research URL

CVE-2021-24502

Published on
Aug 09, 2021
Research Description
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
Affected versions
max 1.7.7.
Status
vulnerable