SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24383

The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

MEDIUM 5.4EPSS 2.47%

Does this matter?

Lower severity and a low EPSS score (2.47%). Track it; it rarely justifies an emergency change on its own.

Description

The WP Google Maps WordPress plugin before 8.1.12 did not sanitise, validate of escape the Map Name when output in the Map List of the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
2.47% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
codecabin/wp go maps
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.