CVE-2025-3502: WP Maps < 4.7.2 - Admin+ Stored XSS
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3502?
CVE-2025-3502 has been categorized as a high severity vulnerability due to its potential to allow Stored Cross-Site Scripting attacks by high privilege users.
How do I fix CVE-2025-3502?
To fix CVE-2025-3502, update the WP Maps WordPress plugin to version 4.7.2 or later, ensuring that proper sanitization and escaping are implemented.
Who is affected by CVE-2025-3502?
CVE-2025-3502 affects installations of the WP Maps WordPress plugin prior to version 4.7.2, particularly on sites where admin users are present.
What type of attack can exploit CVE-2025-3502?
CVE-2025-3502 can be exploited to conduct Stored Cross-Site Scripting attacks, allowing attackers to inject malicious scripts into map settings.
What software version should I upgrade to avoid CVE-2025-3502?
You should upgrade to WP Maps WordPress plugin version 4.7.2 or higher to mitigate the risks associated with CVE-2025-3502.