CVE-2026-102395: WordPress Easy Google Maps plugin <= 1.14.6 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Easy Google Maps pluginto a version that resolves this vulnerability.Fixed in 1.15.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The issue is described as unauthenticated, so an attacker does not need a WordPress account or plugin privileges. The CVSS vector indicates that user interaction is required.
Which installations are affected?
Easy Google Maps plugin versions 1.14.6 and earlier are affected. The supplied information does not identify any configuration prerequisite or workaround.
What impact can successful exploitation have?
The vulnerability is an XSS issue with low confidentiality, integrity, and availability impact in the provided CVSS vector. Its scope is changed, meaning the impact can extend beyond the vulnerable component.