CVE-2025-2279: Maps - Google Maps <= 1.0.6 - Contributor+ Stored XSS
The Maps WordPress plugin through 1.0.6 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2279?
CVE-2025-2279 is classified as a medium severity vulnerability due to the risk of Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-2279?
To fix CVE-2025-2279, update the Maps plugin to version 1.0.7 or later to ensure proper validation and escaping of shortcode attributes.
Who is affected by CVE-2025-2279?
Users with contributor role and above in WordPress can exploit CVE-2025-2279 to execute stored XSS attacks.
What does CVE-2025-2279 exploit?
CVE-2025-2279 exploits a lack of validation and escaping of shortcode attributes in the Maps WordPress plugin.
When was CVE-2025-2279 reported?
CVE-2025-2279 was reported affecting the Maps plugin version up to 1.0.6.