CVE-2025-32138: WordPress Easy Google Maps plugin <= 1.11.18 - XML External Entity vulnerability
Published Apr 4, 2025
·Updated
Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue affects Easy Google Maps: from n/a through <= 1.11.18.
Affected Software
1 affected component
Supsystic Easy Google Maps (google-maps-easy)<=1.11.18
Event History
Apr 4, 2025
CVE Published
via MITRE·03:58 PM
Data Sourced
via MITRE·03:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-32138?
CVE-2025-32138 is considered a critical vulnerability due to its potential to allow XML Injection attacks.
2
How do I fix CVE-2025-32138?
To fix CVE-2025-32138, update your Easy Google Maps plugin to version 1.11.18 or later.
3
What specific versions of Easy Google Maps are affected by CVE-2025-32138?
CVE-2025-32138 affects Easy Google Maps versions from n/a up to 1.11.17.
4
What type of vulnerability is CVE-2025-32138?
CVE-2025-32138 is classified as an Improper Restriction of XML External Entity Reference vulnerability.
5
Can CVE-2025-32138 lead to data exposure?
Yes, CVE-2025-32138 can lead to data exposure via XML Injection if exploited.