CVE-2023-23878: WordPress WP Google Map Plugin Plugin <= 4.3.9 is vulnerable to Cross Site Scripting (XSS)
Published Apr 4, 2023
·Updated
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
Affected Software
2 affected components
flippercode Wp Google Map Wordpress<4.4.0
Weplugins Wp Maps Wordpress<4.4.0
Remediation
Information
Update to 4.4.0 or a higher version.
Event History
Apr 4, 2023
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23878.
2
What is the severity of CVE-2023-23878?
The severity of CVE-2023-23878 is medium with a CVSS score of 5.4.
3
What is the affected software of CVE-2023-23878?
The affected software of CVE-2023-23878 is the flippercode WordPress Plugin for Google Maps - WP MAPS plugin versions <= 4.3.9.
4
What is the CWE category of CVE-2023-23878?
The CWE category of CVE-2023-23878 is CWE-79 (Cross-Site Scripting (XSS)).
5
How can I fix CVE-2023-23878?
To fix CVE-2023-23878, update the flippercode WordPress Plugin for Google Maps - WP MAPS plugin to version 4.4.0 or later.