CVE-2023-2899: Google Map Shortcode <= 3.1.2 - Contributor+ Stored XSS
The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Google Map Shortcode WordPress plugin?
The vulnerability ID for the Google Map Shortcode WordPress plugin is CVE-2023-2899.
What is the severity of CVE-2023-2899?
The severity of CVE-2023-2899 is medium.
How does CVE-2023-2899 impact the Google Map Shortcode WordPress plugin?
CVE-2023-2899 allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks, which could be used against high priority targets.
Which version of the Google Map Shortcode WordPress plugin is affected by CVE-2023-2899?
The Google Map Shortcode WordPress plugin version 3.1.2 and earlier are affected by CVE-2023-2899.
How can I fix the vulnerability in the Google Map Shortcode WordPress plugin?
To fix the vulnerability, update the Google Map Shortcode WordPress plugin to version 3.1.3 or newer.