CVE-2021-24502: WP Google Map < 1.7.7 - Authenticated Stored Cross-Site Scripting (XSS)
Published Aug 9, 2021
·Updated
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfilteredhtml capability is disallowed
Affected Software
2 affected components
flippercode Wp Google Map Wordpress<1.7.7
Weplugins Wp Maps Wordpress<1.7.7
Event History
Aug 9, 2021
CVE Published
via MITRE·10:04 AM
Data Sourced
via MITRE·10:04 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the WP Google Map WordPress plugin?
The vulnerability ID for the WP Google Map WordPress plugin is CVE-2021-24502.
2
What is the severity of CVE-2021-24502?
The severity of CVE-2021-24502 is medium with a CVSS score of 4.8.
3
What is the affected software for CVE-2021-24502?
The affected software for CVE-2021-24502 is Flippercode WP Google Map plugin before version 1.7.7.
4
What is the impact of CVE-2021-24502?
CVE-2021-24502 allows high privilege users to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed.
5
How can I fix CVE-2021-24502?
To fix CVE-2021-24502, update the Flippercode WP Google Map plugin to version 1.7.7 or higher.