First published: Mon May 14 2018(Updated: )
Cross-site scripting vulnerability in WP Google Map Plugin prior to version 4.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
WP Google Map | <4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0577 is a cross-site scripting vulnerability in the WP Google Map Plugin prior to version 4.0.4 for WordPress.
CVE-2018-0577 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which can lead to unauthorized access, data leakage, or website defacement.
CVE-2018-0577 has a severity score of 5.4 (medium).
To fix CVE-2018-0577, update to version 4.0.4 or later of the WP Google Map Plugin for WordPress.
You can find more information about CVE-2018-0577 on the following references: [1] http://jvn.jp/en/jp/JVN01040170/index.html [2] https://wordpress.org/plugins/wp-google-map-plugin/#developers [3] https://wpvulndb.com/vulnerabilities/9610