First published: Mon Aug 09 2021(Updated: )
The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Google Map | <1.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the WP Google Map WordPress plugin is CVE-2021-24502.
The severity of CVE-2021-24502 is medium with a CVSS score of 4.8.
The affected software for CVE-2021-24502 is Flippercode WP Google Map plugin before version 1.7.7.
CVE-2021-24502 allows high privilege users to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed.
To fix CVE-2021-24502, update the Flippercode WP Google Map plugin to version 1.7.7 or higher.