CVE-2025-3504: WP Maps < 4.7.2 - Admin+ Stored XSS
The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3504?
CVE-2025-3504 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2025-3504?
To fix CVE-2025-3504, update the WP Maps plugin to version 4.7.2 or later.
Who is affected by CVE-2025-3504?
CVE-2025-3504 affects users of the WP Maps plugin prior to version 4.7.2, particularly in multisite setups.
What type of attack does CVE-2025-3504 facilitate?
CVE-2025-3504 facilitates Stored Cross-Site Scripting attacks that could be exploited by high privilege users.
Is CVE-2025-3504 exploitable if unfiltered_html capability is disallowed?
Yes, CVE-2025-3504 remains exploitable even when the unfiltered_html capability is disallowed.