VulnerabilityModified
CVE-2023-6627
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.
MEDIUM 6.1EPSS 0.62%
Does this matter?
Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.
Description
The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.28 does not properly protect most of its REST API routes, which attackers can abuse to store malicious HTML/Javascript on the site.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.62% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- codecabin/wp go maps
- Source
- contact@wpscan.com
References
- https://wpscan.com/blog/stored-xss-fixed-in-wp-go-maps-9-0-28/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/f5687d0e-98ca-4449-98d6-7170c97c8f54Exploit, Third Party Advisory
- https://wpscan.com/blog/stored-xss-fixed-in-wp-go-maps-9-0-28/Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/f5687d0e-98ca-4449-98d6-7170c97c8f54Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.