First published: Tue Sep 12 2023(Updated: )
The Google Maps Plugin by Intergeo for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'intergeo' shortcode in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Themeisle Google Maps Plugin By Intergeo | <=2.3.2 | |
<=2.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-4887.
The title of the vulnerability is 'The Google Maps Plugin by Intergeo for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting'.
The severity of CVE-2023-4887 is medium with a severity value of 5.4.
The affected software for CVE-2023-4887 is the Google Maps Plugin by Intergeo for WordPress plugin for WordPress versions up to, and including, 2.3.2.
The vulnerability can be exploited through a Stored Cross-Site Scripting attack by using the 'intergeo' shortcode with insufficient input sanitization and output escaping on user supplied attributes.