CVE-2025-3503: WP Maps < 4.7.2 - Admin+ Stored XSS
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3503?
CVE-2025-3503 is considered a critical vulnerability due to the potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-3503?
To fix CVE-2025-3503, update the WP Maps plugin to version 4.7.2 or later.
Who is affected by CVE-2025-3503?
CVE-2025-3503 affects users of the WP Maps plugin before version 4.7.2, particularly high privilege users like administrators.
What type of attack can be executed due to CVE-2025-3503?
CVE-2025-3503 allows for Stored Cross-Site Scripting attacks, especially in multisite setups.
Is user input validated in the WP Maps plugin due to CVE-2025-3503?
No, CVE-2025-3503 indicates that user input in WP Maps was not effectively sanitized and escaped.